Subscribe via feed.
Archive for January, 2017

Job Portal Script 9.11 SQL Injection

Posted by deepcore under exploit (No Respond)

Job Portal Script version 9.11 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

D-Link DIR-615 Open Redirection / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

D-Link DIR-615 suffers from cross site scripting and open redirection vulnerabilities. Hardware version E3 with firmware version 5.10 is affected.

DiskBoss Enterprise GET Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a stack-based buffer overflow vulnerability in the web interface of DiskBoss Enterprise v7.5.12 and v7.4.28, caused by improper bounds checking of the request path in HTTP GET requests sent to the built-in web server. This Metasploit module has been tested successfully on Windows XP SP3 and Windows 7 SP1.

http://www.thungchang.go.th

Posted by deepcore under defacement (No Respond)

http://www.thungchang.go.th notified by Nofawkx Al

Tags:

http://hangdonghospital.go.th/google46b8ce833112b683.html

Posted by deepcore under defacement (No Respond)

http://hangdonghospital.go.th/google46b8ce833112b683.html notified by Iran Security Team

Tags:

http://sikhiotown.go.th

Posted by deepcore under defacement (No Respond)

http://sikhiotown.go.th notified by Mr.XM404RS!

Tags:

Huawei Flybox B660 – (POST SMS) CSRF Web Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a security flaw that affects the official Huawei Flybox B660 …

Firejail Privilege Escalation

Posted by deepcore under exploit (No Respond)

Firejail suffers from a privilege escalation vulnerability.

VideoLan VLC Media Player 2.2.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Proof of concept .mov that demonstrates a DecodeAdpcmImaQT buffer overflow vulnerability in VideoLAN VLC Media Player version 2.2.1.

Microsoft Windows Kernel win32k.sys NtSetWindowLongPtr Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows kernel win32k.sys NtSetWindowLongPtr privilege escalation exploit that leverages the vulnerability outlined in MS16-135.