Subscribe via feed.
Archive for March, 2017

http://waengcity.go.th/x.txt

Posted by deepcore under defacement (No Respond)

http://waengcity.go.th/x.txt notified by chinafans

Tags:

NetGain Enterprise Manager 7.2.562 Command Execution

Posted by deepcore under exploit (No Respond)

NetGain Enterprise Manager versions 7.2.562 build 853 and below suffer from a ping command injection vulnerability.

Joomla Abstract 2.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Abstract component version 2.1 suffers from a remote SQL injection vulnerability.

Joomla StreetGuessr Game 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla StreetGuessr Game component version 1.0 suffers from a remote SQL injection vulnerability.

Joomla Guesser 1.0.4 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Guesser component version 1.0.4 suffers from a remote SQL injection vulnerability.

Joomla Recipe Manager 2.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Recipe Manager component version 2.2 suffers from a remote SQL injection vulnerability.

pfSense 2.3.2 Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

pfSense version 2.3.2 suffers from cross site request forgery and cross site scripting vulnerabilities that can assist in gaining a reverse-shell remotely as root.

Ektron 8.5 / 8.7 / 9.0 XSLT Transform Remote Code Execution

Posted by deepcore under exploit (No Respond)

Ektron versions 8.5, 8.7 equal to and below sp1, and 9.0 before sp1 have vulnerabilities in various operations within the ServerControlWS.asmxweb services. These vulnerabilities allow for remote code execution without authentication and execute in the context of IIS on the remote system.

http://www.sikhoraphumcity.go.th

Posted by deepcore under defacement (No Respond)

http://www.sikhoraphumcity.go.th notified by Mr.DreamX196

Tags:

WordPress Adminer 1.4.4 Interface Exposure

Posted by deepcore under exploit (No Respond)

WordPress Adminer plugin version 1.4.4 suffers from an interface exposure issue.