Subscribe via feed.
Archive for January, 2017

Cisco Webex Meeting – Open Redirect Web Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a redirect web vulnerability in the official Cisco Webex meet…

Check Box 2016 Q2 Survey Directory Traversal / Open Redirection

Posted by deepcore under exploit (No Respond)

Check Box 2016 Q2 Survey suffers from insecure direct object reference, open redirection, and directory traversal vulnerabilities.

TrueOnline ZyXEL / Billion Command Injection / Default Credentials

Posted by deepcore under exploit (No Respond)

TrueOnline is a Thai ISP that distributes customized versions of ZyXEL and Billion routers – customized with vulnerabilities that is. The routers contain several default administrative accounts and command injections that can be abused by authenticated and unauthenticated attackers.

WordPress WooCommerce Direct Download Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Direct Download for WooCommerce versions up to 1.15 suffer from a local file inclusion vulnerability.

Atlassian Jira 7.1.7 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Atlassian Jira version 7.1.7 suffers from a cross site scripting vulnerability.

dirList 0.3.0 File Upload / Command Execution

Posted by deepcore under exploit (No Respond)

dirList version 0.3.0 suffers from file upload bypass and remote command execution vulnerabilities.

BoZoN 2.4 Remote Command Execution

Posted by deepcore under exploit (No Respond)

BoZon version 2.4 suffers from a pre-authentication remote command execution vulnerability.

http://rayong2.go.th/sht.html

Posted by deepcore under defacement (No Respond)

http://rayong2.go.th/sht.html notified by TheWayEnd

Tags:

Salesforce (Event Registration) Script Insertion

Posted by deepcore under exploit (No Respond)

Salesforce event registration functionality allows for malicious script code to be inserted.

Hassium CMS 0.10 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Hassium CMS version 0.10 suffers from a cross site scripting vulnerability.