Subscribe via feed.
Archive for December, 2016

WordPress Templatic 2.3.6 File Upload

Posted by deepcore under exploit (No Respond)

WordPress Templatic plugin versions 2.3.6 and below suffer from a remote file upload vulnerability.

Dell SonicWALL Global Management System GMS 8.1 Blind SQL Injection

Posted by deepcore under exploit (No Respond)

Dell SonicWALL Global Management System GMS version 8.1 suffers from multiple blind SQL Injection vulnerabilities.

Dell SonicWALL Global Management System GMS 8.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Dell SonicWALL Global Management System GMS version 8.1 suffers from multiple cross site scripting vulnerabilities.

Dell SonicWALL Global Management System GMS 8.1 Adobe Flex SOP Bypass

Posted by deepcore under exploit (No Respond)

Dell SonicWALL GMS versions 8.1 and below are compiled with a vulnerable version of Adobe Flex SDK allowing for same-origin request forgery and cross-site content hijacking.

Dell SonicWALL Network Security Appliance NSA 6600 XSS

Posted by deepcore under exploit (No Respond)

Dell SonicWALL Network Security Appliance NSA 6600 suffers from a reflective cross site scripting vulnerability. Versions affected include NSA 6600 running SonicOS Enhanced 6.2.4.3-31n, WXA 4000 running 1.3.2.0-07, and SafeMode 6.1.0.11.

Dell SonicWALL Secure Mobile Access SMA 8.1 CSRF / XSS

Posted by deepcore under exploit (No Respond)

Dell SonicWALL Secure Mobile Access SMA version 8.1 suffers from cross site request forgery and cross site scripting vulnerabilities.

PHPMailer Remote Code Execution

Posted by deepcore under exploit (No Respond)

PHPMailer versions prior to 5.2.18 remote code execution exploit. Written in python.

Joomla aWeb Cart Watching System For Virtuemart 2.6.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla aWeb Cart Watching System for Virtuemart component version 2.6.0 suffers from a remote SQL injection vulnerability.

SwiftMailer Remote Code Execution

Posted by deepcore under exploit (No Respond)

SwiftMailer versions prior to 5.4.5-DEV suffers from a remote code execution vulnerability.

Popcorn Time 5.6 DLL Hijacking

Posted by deepcore under exploit (No Respond)

Popcorn Time version 5.6 suffers from a dll hijacking vulnerability.