Subscribe via feed.
Archive for October, 2016

Tuleap 8.18 SQL Injection / XSS / Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Analysis of Tuleap versions 8.18 and below remote SQL injection, cross site scripting, and insecure direct object reference vulnerabilities.

LanSpy 2.0.0.155 Buffer Overflow

Posted by deepcore under exploit (No Respond)

LanSpy version 2.0.0.155 local buffer overflow exploit.

SAP Adaptive Server Enterprise 16 Denial Of Service

Posted by deepcore under exploit (No Respond)

An attacker can send a special request to the SAP Adaptive Server Enterprise and crash the server. Version 16 is affected.

SAP EP-RUNTIME 7.5 Denial Of Service

Posted by deepcore under exploit (No Respond)

SAP EP-RUNTIME version 7.5 suffers from a denial of service vulnerability.

SAP NetWeaver KERNEL 7.5 Buffer Overflow

Posted by deepcore under exploit (No Respond)

SAP NetWeaver KERNEL versions 7.0 through 7.5 suffer from a buffer overflow vulnerability.

Pluck CMS 4.7.3 Add-Page Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Pluck CMS version 4.7.3 suffers from an add-page cross site request forgery vulnerability.

OpenNMS Java Object Unserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in the OpenNMS Java object which allows an unauthenticated attacker to run arbitrary code against the system.

Hak5 WiFi Pineapple Preconfiguration Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a login/csrf check bypass vulnerability on WiFi Pineapples versions 2.0 and below and pineapple versions prior to 2.4. These devices may typically be identified by their SSID beacons of ‘Pineapple5_….’; Provided as part of the TospoVirus workshop at DEFCON23.

Hak5 WiFi Pineapple Preconfiguration Command Injection 2

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability on WiFi Pineapples versions 2.0 and below and pineapple versions prior to 2.4. We use a combination of default credentials with a weakness in the anti-csrf generation to achieve command injection on fresh pineapple devices prior to configuration. Additionally if default credentials fail, you can enable a […]

http://www.huayyangkham.go.th/home/includes/editor/assets/HacKeD.html.%2500jpg

Posted by deepcore under defacement (No Respond)

http://www.huayyangkham.go.th/home/includes/editor/assets/HacKeD.html.%2500jpg notified by !~ Ar.H.Hacker ~!

Tags: