Subscribe via feed.
Archive for August, 2016

NUUO NVRmini 2 / NETGEAR ReadyNAS Surveillance Unauthenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

The NVRmini 2 Network Video Recorder and the ReadyNAS Surveillance application are vulnerable to an unauthenticated remote code execution on the exposed web administration interface. This results in code execution as root in the NVRmini and the ‘admin’ user in ReadyNAS. This exploit has been tested on several versions of the NVRmini 2 and the […]

DLL Side Loading In VMware Host Guest Client Redirector

Posted by deepcore under exploit (No Respond)

A DLL side loading vulnerability was found in the VMware Host Guest Client Redirector, a component of VMware Tools. This issue can be exploited by luring a victim into opening a document from the attacker’s share. An attacker can exploit this issue to execute arbitrary code with the privileges of the target user. This can […]

http://www.mkh.go.th/vthai/pic_news/1424538434.html

Posted by deepcore under defacement (No Respond)

http://www.mkh.go.th/vthai/pic_news/1424538434.html notified by RED DEVILS

Tags:

http://nongharn.go.th/personal_pic/73522749IMG_2690.jpg

Posted by deepcore under defacement (No Respond)

http://nongharn.go.th/personal_pic/73522749IMG_2690.jpg notified by RED DEVILS

Tags:

http://ranot.cdd.go.th

Posted by deepcore under defacement (No Respond)

http://ranot.cdd.go.th notified by Rufet Ant

Tags:

Microsoft Education – Stored Cross Site Web Vulnerability

Posted by deepcore under exploit (No Respond)

No abstract description available in the upcomings!

QuickerBB 0.7.0 – Register Cross Site Scripting Vulnerability

Posted by deepcore under exploit (No Respond)

No abstract description available in the upcomings!

EyeLock Myris 3.3.2 SDK Service Unquoted Service Path Privilege Escalation

Posted by deepcore under exploit (No Respond)

EyeLock Myris version 3.3.2 suffers from an unquoted search path issue impacting the service ‘MyrisService’ for Windows deployed as part of Myris solution. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to […]

EyeLock nano NXT 3.5 Local File Disclosure

Posted by deepcore under exploit (No Respond)

nano NXT suffers from a file disclosure vulnerability when input passed thru the ‘path’ parameter to ‘logdownload.php’ script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources.

EyeLock nano NXT 3.5 Remote Root

Posted by deepcore under exploit (No Respond)

EyeLock’s nano NXT firmware latest version 3.5 (released 25.07.2016) suffers from multiple unauthenticated command injection vulnerabilities. The issue lies within the ‘rpc.php’ script located in the ‘/scripts’ directory and can be triggered when user supplied input is not correctly sanitized while updating the local time for the device and/or get info from remote time server. […]