Subscribe via feed.
Archive for March, 2017

Adobe Flash MovieClip Use-After-Free

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a use-after-free in MovieClip attach init object.

Adobe Flash ATF Thumbnailing Heap Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a heap overflow vulnerability in ATF thumbnailing.

Adobe Flash ATF Planar Decompression Heap Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a heap overflow vulnerability in ATF Planar Decompression.

Adobe Flash AVC Header Slicing Heap Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a heap overflow vulnerability in AVC header slicing.

Microsoft Windows COM Session Moniker Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from a COM session moniker elevation of privilege vulnerability.

Apache Struts Jakarta Multipart Parser OGNL Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a remote code execution vulnerability in Apache Struts version 2.3.5 – 2.3.31, and 2.5 – 2.5.10. Remote Code Execution can be performed via http Content-Type header. Native payloads will be converted to executables and dropped in the server’s temp dir. If this fails, try a cmd/* payload, which won’t have to […]

IBM WebSphere Remote Code Execution Java Deserialization

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in IBM’s WebSphere Application Server. An unsafe deserialization call of unauthenticated Java objects exists to the Apache Commons Collections (ACC) library, which allows remote arbitrary code execution. Authentication is not required in order to exploit this vulnerability.

Joomla Vik Rent Car 1.11 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Vik Rent Car component version 1.11 suffers from a remote SQL injection vulnerability.

Joomla Vik Rent Items 1.3 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Vik Rent Items component version 1.3 suffers from a remote SQL injection vulnerability.

Joomla Vik Appointments 1.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Vik Appointments component version 1.5 suffers from a remote SQL injection vulnerability.