Subscribe via feed.
Archive for October, 2016

Yasir Portal 5.0 Portal Scripti Database Disclosure

Posted by deepcore under exploit (No Respond)

Yasir Portal version 5.0 suffers from a database disclosure vulnerability.

XhP CMS 0.5.1 Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

XhP CMS version 0.5.1 suffers from cross site request forgery and cross site scripting vulnerabilities.

Windows NtLoadKeyEx Read Only Hive Arbitrary File Write Privilege Escalation

Posted by deepcore under exploit (No Respond)

NtLoadKeyEx takes a flag to open a registry hive read only, if one of the hive files cannot be opened for read access it will revert to write mode and also impersonate the calling process. This can leading to elevation of privilege if a user controlled hive is opened in a system service.

Windows Edge/IE Isolated Private Namespace Insecure Boundary Descriptor Privilege Escalation

Posted by deepcore under exploit (No Respond)

The isolated private namespace created by ierutils has an insecure boundary descriptor which allows any non-appcontainer sandbox process (such as chrome) or other users on the same system to gain elevated permissions on the namespace directory which could lead to elevation of privilege.

Windows Edge/IE Isolated Private Namespace Insecure DACL Privilege Escalation

Posted by deepcore under exploit (No Respond)

The isolated private namespace created by ierutils has a insecure DACL which allows any appcontainer process to gain elevated permissions on the namespace directory which could lead to elevation of privilege.

SPIP 3.1.2 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

SPIP versions 3.1.2 and below suffer from a cross site request forgery vulnerability.

SPIP 3.1.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SPIP versions 3.1.2 and below suffer from a cross site scripting vulnerability.

SPIP 3.1.2 File Enumeration / Path Traversal

Posted by deepcore under exploit (No Respond)

SPIP versions 3.1.2 and below suffer from file enumeration and path traversal vulnerabilities.

ManageEngine ServiceDesk Plus 9.2 Build 9207 Information Disclosure

Posted by deepcore under exploit (No Respond)

ManageEngine ServiceDesk Plus version 9.2 build 9207 suffers from an unauthorized information disclosure vulnerability.

WineBottler 1.8-rc4 Man-In-The-Middle / Code Execution

Posted by deepcore under exploit (No Respond)

WineBottler versions 1.8-rc4 and below suffer from a man-in-the-middle vulnerability that can allow for remote code execution.