Subscribe via feed.
Archive for November, 2016

Google Chrome Blink Serializer::doSerialize Bad Cast

Posted by deepcore under exploit (No Respond)

When serializing JavaScript objects for sending to another window using the postMessage method, the code in blink does not handle Symbol objects correctly and attempts to serialize this kind of object as a regular object, which results in a bad cast. An attacker that can trigger this issue may be able to execute arbitrary code. […]

Trango Systems Backdoor Root Account

Posted by deepcore under exploit (No Respond)

Trango devices all have a built-in, hidden root account, with a default password that is the same across many devices and software revisions. This account is accessible via ssh and grants access to the underlying embedded unix OS on the device, allowing full control over it. Recent software updates for some models have changed this […]

ShopZilla Comparision Shopping Script 2.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ShopZilla Comparison Shopping Script version 2.3 suffers from a cross site scripting vulnerability.

Rate-Me PHP Script 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Rate-Me PHP Script version 1.0 suffers from a persistent cross site scripting vulnerability.

InvoicePlane 1.4.8 Incorrect Access Control

Posted by deepcore under exploit (No Respond)

InvoicePlane version 1.4.8 has an incorrect access control for password resets.

Sagem Fast 3304-V2 Credential Disclosure

Posted by deepcore under exploit (No Respond)

Sagem Fast 3304-V2 suffers from a credential disclosure vulnerability.

LSASS SMB NTLM Exchange Remote Memory Corruption

Posted by deepcore under exploit (No Respond)

A vulnerability in Windows Local Security Authority Subsystem Service (LSASS) was found on Windows OS versions ranging from Windows XP through to Windows 10. This vulnerability allows an attacker to remotely crash the LSASS.EXE process of an affected workstation with no user interaction. Successful remote exploitation of this issue will result in a reboot of […]

Microsoft Windows kernel win32k Denial Of Service

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a denial of service vulnerability as outlined in MS16-135.

ATutor 2.2.2 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

ATutor version 2.2.2 cross site request forgery proof of concept that adds a new course.

Schoolhos CMS 2.29 Remote Code Execution / SQL Injection

Posted by deepcore under exploit (No Respond)

Schoolhos CMS version 2.29 suffers from code execution and remote SQL injection vulnerabilities.