Subscribe via feed.
Archive for March, 2017

GitHub Enterprise 2.8.x Remote Code Execution

Posted by deepcore under exploit (No Respond)

GitHub Enterprise versions 2.8.x prior to 2.8.6 suffer from a remote code execution vulnerability.

Steam Profile Integration 2.0.11 SQL Injection

Posted by deepcore under exploit (No Respond)

Steam Profile Integration version 2.0.11 suffers from a remote SQL injection vulnerability.

Sitecore Experience Platform 8.1 Update-3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sitecore Experience Platform version 8.1 Update-3 suffers from a cross site scripting vulnerability.

Microsoft Edge Undefined Behavior On Getters

Posted by deepcore under exploit (No Respond)

Microsoft Edge has some undefined behavior on some getters.

AppSamvid DLL Hijacking

Posted by deepcore under exploit (No Respond)

AppSamvid suffers from a dll hijacking vulnerability.

Microsoft Edge Charkra Incorrect Jit Optimization

Posted by deepcore under exploit (No Respond)

Microsoft Edge suffers from a Chakra incorrect jit optimization with TypedArray setter.

WordPress Membership Simplified 1.58 Arbitrary File Download

Posted by deepcore under exploit (No Respond)

WordPress Membership Simplified plugin version 1.58 suffers from an arbitrary file download vulnerability.

Microsoft Internet Information Services Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Microsoft Internet Information Services web server suffers from a cross site scripting vulnerability.

Windows DVD Maker 6.1.7 XXE Injection

Posted by deepcore under exploit (No Respond)

Windows DVD Maker version 6.1.7 suffers from an XML external entity injection vulnerability.

AXIS Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Various AXIS cameras suffer from cross site request forgery and cross site scripting vulnerabilities amongst other issues.