Subscribe via feed.
Archive for December, 2016

PHPMailer 5.2.17 Remote Code Execution

Posted by deepcore under exploit (No Respond)

PHPMailer version 5.2.17 suffers from a remote code execution vulnerability.

http://umjan.go.th

Posted by deepcore under defacement (No Respond)

http://umjan.go.th notified by Krypton

Tags:

http://dhr.go.th

Posted by deepcore under defacement (No Respond)

http://dhr.go.th notified by Krypton

Tags:

http://namon.go.th

Posted by deepcore under defacement (No Respond)

http://namon.go.th notified by Krypton

Tags:

http://www.phachi.go.th

Posted by deepcore under defacement (No Respond)

http://www.phachi.go.th notified by Krypton

Tags:

XAMPP Control Panel Denial Of Service

Posted by deepcore under exploit (No Respond)

XAMPP Control Panel suffers from a denial of service vulnerability.

http://www.khanom.go.th/usronline.php

Posted by deepcore under defacement (No Respond)

http://www.khanom.go.th/usronline.php notified by freemandz

Tags:

Nidesoft MP3 Converter 2.6.18 DLL Hijacking

Posted by deepcore under exploit (No Respond)

Nidesoft MP3 Converter version 2.6.18 suffers from a dll hijacking vulnerability.

OpenSSH Arbitrary Library Loading

Posted by deepcore under exploit (No Respond)

The OpenSSH agent permits its clients to load PKCS11 providers using the commands SSH_AGENTC_ADD_SMARTCARD_KEY and SSH_AGENTC_ADD_SMARTCARD_KEY_CONSTRAINED if OpenSSH was compiled with the ENABLE_PKCS11 flag (normally enabled) and the agent isn’t locked. For these commands, the client has to specify a provider name. Th e agent passes this provider name to a subprocess (via ssh-agent.c:process_add_smartcard_key -> […]

OpenSSH Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

OpenSSH can forward TCP sockets and UNIX domain sockets. If privilege separation is disabled, then on the server side, the forwarding is handled by a child of sshd that has root privileges. For TCP server sockets, sshd explicitly checks whether an attempt is made to bind to a low port (below IPPORT_RESERVED) and, if so, […]