Subscribe via feed.
Archive for September, 2016

AnoBBS 1.0.1 Remote File Inclusion

Posted by deepcore under exploit (No Respond)

AnoBBS version 1.0.1 suffers from a remote file inclusion vulnerability.

MP3 Cutter 1.1.0 Registration Bypass

Posted by deepcore under exploit (No Respond)

MP3 Cutter version 1.1.0 suffers from a registration bypass flaw.

Cisco ASA 9.2(3) EXTRABACON Module / Authentication Bypass

Posted by deepcore under exploit (No Respond)

This is an additional EXTRABACON module for Cisco ASA version 9.2(3). This does not use the same shellcode as the Equation Group version, but accomplishes the same task of disabling the auth functions in less stages/bytes.

Peel Shopping 8.0.2 Object Injection

Posted by deepcore under exploit (No Respond)

Peel Shopping version 8.0.2 suffers from an object injection vulnerability.

Kajona 4.7 Cross Site Scripting / Directory Traversal

Posted by deepcore under exploit (No Respond)

Kajona version 4.7 suffers from cross site scripting and directory traversal vulnerabilities.

MyBB 1.8.6 Cross Site Request Forgery / Weak Hashing

Posted by deepcore under exploit (No Respond)

MyBB version 1.8.6 suffers from a cross site request forgery vulnerability. Additionally, it stores passwords using weak hashing and sends password in clear text via email.

MyBB 1.8.6 SQL Injection

Posted by deepcore under exploit (No Respond)

MyBB version 1.8.6 suffers from a remote SQL injection vulnerability.

MyBB 1.8.6 Data Validation

Posted by deepcore under exploit (No Respond)

MyBB version 1.8.6 suffers from improper validation of data passed to eval allowing for the disclosure of the database password.

Oxwall 1.8.0 Build 9900 Cross Site Scripting / Open Redirect

Posted by deepcore under exploit (No Respond)

Oxwall version 1.8.0 build 9900 suffers from cross site scripting and open redirection vulnerabilities.

Docker Daemon Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module obtains root privileges from any host account with access to the Docker daemon. Usually this includes accounts in the docker group.