Subscribe via feed.
Archive for November, 2016

Tenda, Dlink & Tplink TD-W8961ND – DHCP XSS Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory research team discovered a persistent xss vulnerability in the Tenda, Dlink & Tplink 1.0.1 …

Burden TMA v2.1.1 – (Task) Persistent Web Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered persistent input validation web vulnerability in the Burden v…

http://www.smartfarmer.doae.go.th/sh.html

Posted by deepcore under defacement (No Respond)

http://www.smartfarmer.doae.go.th/sh.html notified by Shade

Tags:

http://www.muangaranyik.go.th/index.php

Posted by deepcore under defacement (No Respond)

http://www.muangaranyik.go.th/index.php notified by @CHR@F

Tags:

NodCMS Installer Client-Side Cross Site Scripting

Posted by deepcore under exploit (No Respond)

NodCMS Installer suffers from a client-side cross site scripting vulnerability.

Microsoft Internet Explorer 8 MSHTML Ptls5::LsFindSpanVisualBoundaries Memory Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer 8 suffers from an MSHTML Ptls5::LsFindSpanVisualBoundaries memory corruption vulnerability.

WonderCMS 0.9.8 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WonderCMS versions 0.9.8 and below suffer from a cross site scripting vulnerability.

ntpd 4.2.7.p22 / 4.3.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

ntpd versions 4.2.7p22 up to but not including 4.2.8p9 and 4.3.0 up to, but not including 4.3.94 suffer from a remote denial of service vulnerability. The vulnerability allow unauthenticated users to crash ntpd with a single malformed UDP packet, which cause a null pointer dereference.

Huawei UTPS UTPS-V200R003B015D16SPC00C983 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Huawei UTPS software version UTPS-V200R003B015D16SPC00C983 suffers from an unquoted service path privilege escalation vulnerability.

Crestron AM-100 1.2.1 Path Traversal / Hard-Coded Credentials

Posted by deepcore under exploit (No Respond)

Crestron AM-100 versions 1.1.1.11 through 1.2.1 suffer from hard-coded credential and path traversal vulnerabilities.