Subscribe via feed.
Archive for August, 2016

Zabbix 3.0.3 SQL Injection

Posted by deepcore under exploit (No Respond)

Zabbix version 3.0.3 suffers from a remote SQL injection vulnerability.

Apache OpenMeetings 3.1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Apache OpenMeetings version 3.1.0 suffers from a cross site scripting vulnerability.

FreePBX 13 / 14 Remote Command Execution

Posted by deepcore under exploit (No Respond)

FreePBX versions 13 and 14 remote command execution exploit.

WebNMS Framework Server 5.2 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module abuses a vulnerability in WebNMS Framework Server 5.2 that allows an unauthenticated user to upload text files by using a directory traversal attack on the FileUploadServlet servlet. A JSP file can be uploaded that then drops and executes a malicious payload, achieving code execution under the user which the WebNMS server is […]

[webapps] – FreePBX 13 / 14 – Remote Code Execution

Posted by deepcore under Security (No Respond)

FreePBX 13 / 14 – Remote Code Execution

Tags: ,

[remote] – Apache + PHP < 5.3.12 / < 5.4.2 – Remote Code Execution (Multithreaded Scanner) (2)

Posted by deepcore under Security (No Respond)

Apache + PHP < 5.3.12 / < 5.4.2 – Remote Code Execution (Multithreaded Scanner) (2)

Tags: ,

[remote] – Easy FTP Server – "APPE" Command Buffer Overflow Remote Exploit

Posted by deepcore under Security (No Respond)

Easy FTP Server – “APPE” Command Buffer Overflow Remote Exploit

Tags: ,

SAP CAR Archive Tool Denial Of Service / Security Bypass

Posted by deepcore under exploit (No Respond)

SAP CAR archive tool suffers from security bypass and denial of service vulnerabilities.

Netcore Router Udp 53413 Backdoor

Posted by deepcore under exploit (No Respond)

Routers manufactured by Netcore, a popular brand for networking equipment in China, have a wide-open backdoor that can be fairly easily exploited by attackers. These products are also sold under the Netis brand name outside of China. This backdoor allows cyber criminals to easily run arbitrary code on these routers, rendering it vulnerable as a […]

NUUO NVRmini 2 / Crystal / NETGEAR ReadyNAS Surveillance Authenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

The NVRmini 2 Network Video Recorder, Crystal NVR and the ReadyNAS Surveillance application are vulnerable to an authenticated remote code execution on the exposed web administration interface. An administrative account is needed to exploit this vulnerability. This results in code execution as root in the NVRmini and the ‘admin’ user in ReadyNAS. This exploit has […]