Subscribe via feed.
Archive for September, 2016

Kaspersky Company Account – FileManager Vulnerability

Posted by deepcore under exploit (No Respond)

No abstract description available in the upcomings!

FormatFactory 3.9.0 – (.task) Stack Overflow Vulnerability

Posted by deepcore under exploit (No Respond)

No abstract description available in the upcomings!

FormatFactory 3.9.0 – (.task) Stack Overflow Vulnerability

Posted by deepcore under exploit (No Respond)

No abstract description available in the upcomings!

Avira Free Antivirus DLL Hijacking

Posted by deepcore under exploit (No Respond)

Avira’s free antivirus package installers suffer from a dll hijacking vulnerability.

Joomla JSJobs 1.0.7.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla JSJobs component version 1.0.7.5 suffers from a remote SQL injection vulnerability.

CactuShop 7 Database Disclosure

Posted by deepcore under exploit (No Respond)

CactuShop version 7 suffers from a database disclosure vulnerability.

ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

ZKTime.Net suffers from an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘C’ flag (Change) for ‘Everyone’ group, making the entire directory ‘ZKTimeNet3.0’ and its files and sub-dirs world-writable. Version […]

ZKTeco ZKAccess Professional 3.5.3 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

ZKAccess suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘M’ flag (Modify) for ‘Authenticated Users’ group. Version 3.5.3 is affected.

ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote SYSTEM Code Execution

Posted by deepcore under exploit (No Respond)

The ZKBioSecurity solution suffers from a use of hard-coded credentials. The application comes bundled with a pre-configured apache tomcat server and an exposed ‘manager’ application that after authenticating with the credentials: username: zkteco, password: zkt123, located in tomcat-users.xml file, it allows malicious WAR archive containing a JSP application to be uploaded, thus giving the attacker […]

ZKTeco ZKBioSecurity 3.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ZKBioSecurity suffers from multiple reflected cross site scripting vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site. Version 3.0.1.0_R_230 is affected.