Subscribe via feed.
Archive for March, 2017

QNAP QTS Privilege Escalation / Information Disclosure

Posted by deepcore under exploit (No Respond)

QNAP QTS versions prior to 4.2.4 suffer from a sensitive data exposure vulnerability that allows for privilege escalation.

http://plan.correct.go.th

Posted by deepcore under defacement (No Respond)

http://plan.correct.go.th notified by RxR

Tags:

GLink Word Link Script 1.2.3 SQL Injection

Posted by deepcore under exploit (No Respond)

GLink Word Link Script version 1.2.3 suffers from a remote SQL injection vulnerability.

Joomla Extra Search 2.2.8 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Extra Search component version 2.2.8 suffers from a remote SQL injection vulnerability.

LastPass websiteConnector.js RPC Command Proxy

Posted by deepcore under exploit (No Respond)

websiteConnector.js content script in LastPass allows for proxying of internal RPC commands.

OpenSSH On Cygwin SFTP Client Directory Traversal

Posted by deepcore under exploit (No Respond)

Portable OpenSSH supports running on Cygwin. However, the SFTP client only filters out forward slashes (in do_lsreaddir()) and the directory names “.” and “..” (in download_dir_internal()). On Windows, including in Cygwin, backslashes can a lso be used for directory traversal.

Disk Sorter Enterprise 9.5.12 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Disk Sorter Enterprise version 9.5.12 GET buffer overflow SEH exploit.

Solar-Log CSRF / Information Disclosure / DoS / File Upload

Posted by deepcore under exploit (No Respond)

Solare Datensysteme GmbH Solar-Log versions 250, 300, 500, 800e, 1000, 1000 PM+, 1200, and 2000 suffer from cross site request forgery, cross site scripting, file upload, information disclosure, and denial of service vulnerabilities.

SysGauge SMTP Validation Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module will setup an SMTP server expecting a connection from SysGauge 1.5.18 via its SMTP server validation. The module sends a malicious response along in the 220 service ready response and exploits the client, resulting in an unprivileged shell.

Windows 10: DoubleAgent Zero-Day Hijacks Microsoft Tool To Turn Antivirus Into Malware

Posted by deepcore under exploit (No Respond)