Subscribe via feed.
Archive for November, 2016

WordPress Image Gallery 1.9.65 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Image Gallery plugin version 1.9.65 suffers from a persistent cross site scripting vulnerability.

Gstreamer Heap Corruption

Posted by deepcore under exploit (No Respond)

A full analysis and proof of concept 0-day exploits for a heap corruption vulnerability in the gstreamer decoder.

Linux ntpd 4.2.8 derive_nonce Stack Overflow

Posted by deepcore under exploit (No Respond)

Linux ntpd 4.2.8 derive_nonce remote stack overflow proof of concept exploit.

HS-110 Smart Plug Account Takeover / Insecure Design

Posted by deepcore under exploit (No Respond)

This is an interesting analysis that goes over reverse engineering access to the HS-110 Smart Plug and how secrets are insecurely transferred.

Microsoft Internet Explorer 10 MSHTML CEditAdorner::Detach Use-After-Free

Posted by deepcore under exploit (No Respond)

A specially crafted web-page can cause Microsoft Internet Explorer 10 to continue to use an object after freeing the memory used to store the object. An attacker might be able to exploit this issue to execute arbitrary code.

Koken 0.22.7 / 0.22.11 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Koken versions 0.22.7 and 0.22.11 suffer from multiple cross site scripting vulnerabilities.

Microsoft Internet Explorer 11 MSHTML CGeneratedContent::HasGeneratedSVGMarker Type Confusion

Posted by deepcore under exploit (No Respond)

A specially crafted web-page can cause a type confusion in HTML layout in Microsoft Internet Explorer 11. An attacker might be able to exploit this issue to execute arbitrary code.

Osticket 1.9.14 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Osticket versions 1.9.14 and below X-Forwarded-For stored cross site scripting exploit.

Less.js Untrusted File Compilation / Code Execution

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered behavior in the Less.js compiler, which allows execution of arbitrary code if an untrusted LESS file is compiled.

chatNow v1.1 – SQL Injection Web Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a remote sql-injection vulnerability in the official chatN…