Subscribe via feed.
Archive for January, 2017

http://samor.go.th/media/

Posted by deepcore under defacement (No Respond)

http://samor.go.th/media/ notified by sy.t

Tags:

SoftMaker Office 201x Privilege Escalation

Posted by deepcore under exploit (No Respond)

SoftMaker Office 201x suffers from a local privilege escalation vulnerability due to an unprotected directory.

TinyPDF Installer DLL Hijacking / Unsafe Temp Directory

Posted by deepcore under exploit (No Respond)

InstallTinyPDF.exe suffers from dll hijacking and unsafe temp directory vulnerabilities.

Atlassian Confluence 5.9.12 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Tempest Security Intelligence Advisory ADV-3/2016 – Atlassian Confluence version 5.9.12 is vulnerable to persistent cross site scripting because it fails to securely validate user controlled data, thus making it possible for an attacker to supply crafted input in order to harm users. The bug occurs at pages carrying attached files, even though the attached file […]

WordPress Stop User Enumeration 1.3.4 User Enumeration

Posted by deepcore under exploit (No Respond)

WordPress Stop User Enumeration plugin version 1.3.4 fails to stop user enumeration.

Zyxel/Eir D1000 DSL Modem NewNTPServer Command Injection Over TR-064

Posted by deepcore under exploit (No Respond)

Broadband DSL modems manufactured by Zyxel and distributed by some European ISPs are vulnerable to a command injection vulnerability when setting the ‘NewNTPServer’ value using the TR-64 SOAP-based configuration protocol. In the tested case, no authentication is required to set this value on affected DSL modems. This exploit was originally tested on firmware versions up […]

PDFAdd 1.2 DLL Hijacking

Posted by deepcore under exploit (No Respond)

PDFAdd version 1.2 suffers from a dll hijacking vulnerability.

My Click Counter 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

My Click Counter version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Internet Download Accelerator 6.10.1.1527 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Internet Download Accelerator version 6.10.1.1527 SEH FTP buffer overflow exploit.

Samsung OTP Service Heap Overflow

Posted by deepcore under exploit (No Respond)

As a part of the KNOX extensions available on Samsung devices, Samsung provides a new service which allows the generation of OTP tokens and suffers from a heap overflow vulnerability.