Subscribe via feed.
Archive for August, 2016

NASdeluxe NDL-2400r 2.01.10 Command Injection

Posted by deepcore under exploit (No Respond)

NASdeluxe NDL-2400r version 2.01.10 suffers from an OS command injection vulnerability.

ntop 2.5 Cross Site Request Forgery / Command Execution

Posted by deepcore under exploit (No Respond)

ntop versions 2.3 through 2.5 suffer from cross site request forgery and multiple command execution vulnerabilities.

PHP Power Browse 1.2 Path Traversal

Posted by deepcore under exploit (No Respond)

PHP Power Browse version 1.2 suffers from a path traversal vulnerability.

Davolink DV-2051 Missing Access Control

Posted by deepcore under exploit (No Respond)

Davolink DV-2051 suffers from a missing access control vulnerability.

SMB Delivery Module

Posted by deepcore under exploit (No Respond)

This Metasploit module serves payloads via an SMB server and provides commands to retrieve and execute the generated payloads. Currently supports DLLs and Powershell.

Internet Explorer 11 VBScript Engine Memory Corruption

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits the memory corruption vulnerability (CVE-2016-0189) present in the VBScript engine of Internet Explorer 11.

Samsung Security Manager 1.5 ActiveMQ Broker Service PUT Method Remote Code Execution

Posted by deepcore under exploit (No Respond)

This is an exploit against Samsung Security Manager that bypasses the patch in CVE-2015-3435 by exploiting the vulnerability against the client side. This exploit has been tested successfully against IE, FireFox and Chrome by abusing a GET request XSS to bypass CORS and reach the vulnerable PUT. Finally, a traversal is used in the PUT […]

http://www.dgr.go.th/bgepa/chaing_rai/index.html

Posted by deepcore under defacement (No Respond)

http://www.dgr.go.th/bgepa/chaing_rai/index.html notified by islamic ghosts team

Tags:

[webapps] – NUUO NVRmini 2 3.0.8 – Local File Disclosure

Posted by deepcore under Security (No Respond)

NUUO NVRmini 2 3.0.8 – Local File Disclosure

Tags: ,

[webapps] – NUUO NVRmini 2 3.0.8 – Arbitrary File Deletion

Posted by deepcore under Security (No Respond)

NUUO NVRmini 2 3.0.8 – Arbitrary File Deletion

Tags: ,