Subscribe via feed.
Archive for February, 2017

Elefant CMS 1.3.12-RC Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Elefant CMS version 1.3.12-RC suffers from multiple persistent cross site scripting vulnerabilities.

Simplessus Files 3.7.7 Path Traversal

Posted by deepcore under exploit (No Respond)

Simplessus Files version 3.7.7 suffers from a path traversal vulnerability.

Elefant CMS 1.3.12-RC Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Elefant CMS version 1.3.12-RC suffers from multiple cross site request forgery vulnerabilities.

Microsoft SQL Server Clr Stored Procedure Payload Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module executes an arbitrary native payload on a Microsoft SQL server by loading a custom SQL CLR Assembly into the target SQL installation, and calling it directly with a base64-encoded payload. The module requires working credentials in order to connect directly to the MSSQL Server. This method requires the user to have sufficient […]

Plone 5.0.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Plone version 5.0.5 suffers from a cross site scripting vulnerability.

Elefant CMS 1.3.12-RC Code Execution

Posted by deepcore under exploit (No Respond)

Elefant CMS version 1.3.12-RC suffers from remote code execution vulnerabilities.

Microsoft Office 2010 MSO!Ordinal5429 Heap Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Office 2010 running under Windows 7 x86 with Application Verifier enabled suffers from a heap corruption issue due to a missing length check.

Microsoft Office Powerpoint 2010 MSO/OART Heap Out-Of-Bounds Access

Posted by deepcore under exploit (No Respond)

Microsoft Office 2010 running under Windows 7 x86 with Application Verifier enabled suffers from a heap out-of-bounds access issue that leads to a memory corruption condition.

GDI GDI32!ConvertDxArray Insufficient Bounds Check

Posted by deepcore under exploit (No Respond)

GDI suffers from an insufficient bounds check on GDI32!ConvertDxArray.

Google Chrome Download Filetype Blacklist Bypass

Posted by deepcore under exploit (No Respond)

Google Chrome suffers from a bypass vulnerability in the download filetype blacklist functionality. Versions 54.0.2840.100 stable is affected.