Subscribe via feed.
Archive for November, 2016

OpManager 12100 / 12200 Cross Site Scripting / Denial Of Service

Posted by deepcore under exploit (No Respond)

OpManager versions 12100 and 12200 suffer from multiple cross site scripting and denial of service vulnerabilities.

ScriptCase CSRF / XSS / SQL Injection

Posted by deepcore under exploit (No Respond)

ScriptCase versions 8.1.053, 8.1.051, and 8.1.43.0 suffer from token bypass, user enumeration, local privilege escalation, cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.

Putty 0.67 Cleartext Password Storage

Posted by deepcore under exploit (No Respond)

Putty version 0.67 suffers from a cleartext password storage vulnerability.

Multitech RightFax Faxfinder Credential Disclosure

Posted by deepcore under exploit (No Respond)

Multitech RightFax Faxfinder versions prior to 4.1.2 suffer from a clear-text credential disclosure vulnerability.

Dlink DIR Routers Unauthenticated HNAP Login Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

Several Dlink routers contain a pre-authentication stack buffer overflow vulnerability, which is exposed on the LAN interface on port 80. This vulnerability affects the HNAP SOAP protocol, which accepts arbitrarily long strings into certain XML parameters and then copies them into the stack. This exploit has been tested on the real devices DIR-818LW and 868L […]

Atlassian Confluence AppFusions Doxygen 1.3.0 Path Traversal

Posted by deepcore under exploit (No Respond)

Atlassian Confluence AppFusions Doxygen version 1.3.0 suffers from a path traversal vulnerability.

Atlassian Confluence AppFusions Doxygen 1.3.x Information Disclosure

Posted by deepcore under exploit (No Respond)

Atlassian Confluence AppFusions Doxygen versions 1.3.0, 1.3.1, 1.3.2, and 1.3.3 suffer from an information disclosure vulnerability.

Atlassian Confluence AppFusions Doxygen 1.3.x Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Atlassian Confluence AppFusions Doxygen versions 1.3.0, 1.3.1, 1.3.2, and 1.3.3 suffer from a cross site scripting vulnerability.

SAP NetWeaver AS JAVA 7.4 Denial Of Service

Posted by deepcore under exploit (No Respond)

SAP NetWeaver AS JAVA version 7.4 suffers from a denial of service vulnerability.

SAP NetWeaver AS JAVA 7.4 XXE Injection

Posted by deepcore under exploit (No Respond)

SAP NetWeaver AS JAVA version 7.4 suffers from an XML external entity (XXE) injection vulnerability.