Subscribe via feed.
Archive for October, 2016

Foxit Cloud Update Service Privilege Escalation

Posted by deepcore under exploit (No Respond)

Foxit Cloud Update Service suffers from an unquoted service path privilege escalation vulnerability.

Fitbit Connect Service Privilege Escalation

Posted by deepcore under exploit (No Respond)

Fitbit Connect Service suffers from an unquoted service path privilege escalation vulnerability.

Apache Tomcat 8 / 7 / 6 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Apache Tomcat versions 8, 7, and 6 suffer from a privilege escalation vulnerability on RedHat-based distros.

HP Client Automation 7.9 Command Injection

Posted by deepcore under exploit (No Respond)

HP Client Automation remote command injection exploit that adds backdoor accounts and provides a reverse shell. Author tested on version 7.9 but believes it should also work on 8.1, 9.0, and 9.1.

ZendStudio IDE 13.5.1 Privilege Escalation

Posted by deepcore under exploit (No Respond)

ZendStudio IDE version 13.5.1 suffers from a privilege escalation vulnerability.

Android Qualcomm GPS/GNSS Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

Android devices can be crashed remotely forcing a halt and then a soft reboot by a MITM attacker manipulating assisted GPS/GNSS data provided by Qualcomm. This issue affects the open source code in AOSP and proprietary code in a Java XTRA downloader provided by Qualcomm. The Android issue was fixed by in the October 2016 […]

Allwinner 3.4 Legacy Kernel Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module attempts to exploit a debug backdoor privilege escalation in Allwinner SoC based devices.

Linux Kernel 3.13.1 Recvmmsg Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module attempts to exploit CVE-2014-0038, by sending a recvmmsg system call with a crafted timeout pointer parameter to gain root. This exploit has offsets for 3 Ubuntu 13 kernels built in: 3.8.0-19-generic (13.04 default) 3.11.0-12-generic (13.10 default) 3.11.0-15-generic (13.10) This exploit may take up to 13 minutes to run due to a decrementing […]

Powershell Payload Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module generates a dynamic executable on the session host using .NET templates. Code is pulled from C

Facebook API v2.1 – RFC6749 Open Redirect Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a RFC6749 Open Redirect Attack & Vulnerability in the Faceboo…