Subscribe via feed.
Archive for January, 2017

OPSI Managed Client Remote Command Execution

Posted by deepcore under exploit (No Respond)

A remote attacker with knowledge of a single machine name and the corresponding OPSI machine key is able to execute arbitrary commands on any OPSI Managed client in the same managed environment by using the Remote Procedure Call (RPC) Interface of the OPSI-Server. The attacker is able to use the SYSTEM privileges of the OPSI […]

PDFMate PDF Converter Pro 1.7.5.0 – Buffer Overflow

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a local buffer overflow vulnerability in the PDFMate PDF Conv…

http://www.kolum.go.th/mary2.php

Posted by deepcore under defacement (No Respond)

http://www.kolum.go.th/mary2.php notified by TheWayEnd

Tags:

http://pakrng.go.th/mrd.php

Posted by deepcore under defacement (No Respond)

http://pakrng.go.th/mrd.php notified by MrD

Tags:

http://singburi.labour.go.th/zeby.php

Posted by deepcore under defacement (No Respond)

http://singburi.labour.go.th/zeby.php notified by Mohamed Riahi

Tags:

http://www.khoktan.go.th/data/

Posted by deepcore under defacement (No Respond)

http://www.khoktan.go.th/data/ notified by !~ Ar.H.Hacker ~!

Tags:

Mac OS / iOS IOService::matchPassive Use-After-Free

Posted by deepcore under exploit (No Respond)

Mac OS / iOS kernels suffer from a use-after-free due to a failure to take reference in IOService::matchPassive.

Mac OS / iOS Kernel Memory Corruption

Posted by deepcore under exploit (No Respond)

Mac OS and iOS kernels suffer from a memory corruption vulnerability due to a userspace pointer being used as a length.

HTTP_Upload 1.0.0.b3 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

HTTP_Upload version 1.0.0b3 fails to appropriately take into consideration more than file extensions when mitigating malicious file uploads, allowing for remote code execution.

Cisco WebEx 1.0.5 Command Execution

Posted by deepcore under exploit (No Respond)

Cisco WebEx version 1.0.5 suffers from a new arbitrary command execution vulnerability via a module whitelist bypass.