Subscribe via feed.
Archive for February, 2017

WordPress 4.7.0 / 4.7.1 REST API Privilege Escalation

Posted by deepcore under exploit (No Respond)

WordPress versions 4.7.0 and 4.7.1 REST API post privilege escalation and defacement exploit. Originally vulnerability discovered by Sucuri’s research team.

Android RKP rkp_set_init_page_ro Memory Corruption

Posted by deepcore under exploit (No Respond)

Android suffers from an RKP related memory corruption vulnerability in rkp_set_init_page_ro.

Packet Storm New Exploits For January, 2017

Posted by deepcore under exploit (No Respond)

This archive contains 229 exploits that were added to Packet Storm in January, 2017.

TrueOnline / ZyXEL P660HN-T v1 Router Unauthenticated Command Injection

Posted by deepcore under exploit (No Respond)

TrueOnline is a major ISP in Thailand, and it distributes a customised version of the ZyXEL P660HN-T v1 router. This customised version has an unauthenticated command injection vulnerability in the remote log forwarding page. This Metasploit module was tested in an emulated environment, as the author doesn’t have access to the Thai router any more. […]

TrueOnline / Billion 5200W-T Router Unauthenticated Command Injection

Posted by deepcore under exploit (No Respond)

TrueOnline is a major ISP in Thailand, and it distributes a customized version of the Billion 5200W-T router. This customized version has at least two command injection vulnerabilities, one authenticated and one unauthenticated, on different firmware versions. This Metasploit module will attempt to exploit the unauthenticated injection first, and if that fails, it will attempt […]

TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection

Posted by deepcore under exploit (No Respond)

TrueOnline is a major ISP in Thailand, and it distributes a customized version of the ZyXEL P660HN-T v2 router. This customized version has an authenticated command injection vulnerability in the remote log forwarding page. This can be exploited using the “supervisor” account that comes with a default password on the device. This Metasploit module was […]

Cisco WebEx Chrome Extension Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability present in the Cisco WebEx Chrome Extension version 1.0.1 which allows an attacker to execute arbitrary commands on a system.

Apple WebKit HTMLKeygenElement Type Confusion

Posted by deepcore under Apple (No Respond)

Apple WebKit suffers from a HTMLKeygenElement type confusion vulnerability.

Tags: , ,

Apple WebKit Renderbox Type Confusion

Posted by deepcore under Apple (No Respond)

Apple WebKit suffers from a type confusion vulnerability in RenderBox with accessibility enabled.

Tags: , ,

Apple WebKit HTMLFormElement::reset() Use-After-Free

Posted by deepcore under Apple (No Respond)

Apple WebKit suffers from a use-after-free vulnerability in HTMLFormElement::reset().

Tags: , ,