Subscribe via feed.
Archive for November, 2016

Android Proxy Auto Config (PAC) Crash

Posted by deepcore under exploit (No Respond)

Android devices can be crashed forcing a halt and then a soft reboot by downloading a large proxy auto config (PAC) file when adjusting the Android networking settings. This can also be exploited by an MITM attacker that can intercept and replace the PAC file. However, the bug is mitigated by multiple factors and the […]

Bart Ransomware (Win32/Filecoder.Bart) (Kidnapping) Resource Hacking

Posted by deepcore under exploit (No Respond)

This report explains the ability to change the code of Bart. An attacker can edit the code and seamlessly put their own dark website with a different Bitcoin account.

WordPress YITH WooCommerce Compare 2.0.9 PHP Object Injection

Posted by deepcore under exploit (No Respond)

WordPress YITH WooCommerce Compare plugin version 2.0.9 suffers from a PHP object injection vulnerability.

WordPress Quotes Collection 2.0.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Quotes Collection plugin version 2.0.5 suffers from a cross site scripting vulnerability.

WordPress Caldera Forms 1.3.5.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Caldera Forms plugin version 1.3.5.3 suffers from a cross site scripting vulnerability.

MOVISTAR ADSL Router BHS_RTA BHS_RTA_C0_019 Remote File Disclosure

Posted by deepcore under exploit (No Respond)

MOVISTAR ADSL router BHS_RTA BHS_RTA_C0_019 suffers from a file disclosure vulnerability.

D-Link ADSL Router DSL-2730U IN_1.02 Remote File Disclosure

Posted by deepcore under exploit (No Respond)

D-Link ADSL router DSL-2730U with firmware version IN_1.02 suffers from a file disclosure vulnerability.

NETGEAR ADSL Router JNR1010 1.0.0.16 Authenticated Remote File Disclosure

Posted by deepcore under exploit (No Respond)

NETGEAR ADSL Router JNR1010 with firmware version 1.0.0.16 suffers from a file disclosure vulnerability.

PLANET ADSL Router AND-4101 1.8 Remote File Disclosure

Posted by deepcore under exploit (No Respond)

PLANET ADSL router AND-4101 version 1.8 suffers from a file disclosure vulnerability.

D-Link ADSL Router DSL-2750E SEA_1.04 Remote File Disclosure

Posted by deepcore under exploit (No Respond)

D-Link ADSL router DSL-2750E with firmware version SEA_1.04 suffers from a file disclosure vulnerability.