Subscribe via feed.
Archive for April, 2017

Agorum Core Pro 7.8.1.4-251 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Agorum Core Pro version 7.8.1.4-251 suffers from a reflective cross site scripting vulnerability.

Agorum Core Pro 7.8.1.4-251 XXE Injection

Posted by deepcore under exploit (No Respond)

Agorum Core Pro version 7.8.1.4-251 suffers from an XML external entity injection vulnerability.

concrete5 8.1.0 Host Header Injection

Posted by deepcore under exploit (No Respond)

concrete5 version 8.1.0 suffers from a host header injection vulnerability.

Microsoft Windows Kernel NtGdiGetDIBitsInternal Memory Disclosure / DoS

Posted by deepcore under exploit (No Respond)

Multiple bugs have been discovered in the implementation of the win32k!NtGdiGetDIBitsInternal system call, which is a part of the graphic subsystem in all modern versions of Windows. The issues can potentially lead to kernel pool memory disclosure or denial of service. Under certain circumstances, memory corruption could also be possible.

Microsoft Windows Kernel win32kfull!SfnINLPUAHDRAWMENUITEM Memory Disclosure

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a stack memory disclosure vulnerability in win32kfull!SfnINLPUAHDRAWMENUITEM.

GNS3 Mac OS-X 1.5.2 ubridge Privilege Escalation

Posted by deepcore under Apple (No Respond)

GNS3 Mac OS-X version 1.5.2 ubridge privilege escalation exploit.

Tags: , ,

XiongMai uc-http 1.0.0 Local File Inclusion / Directory Traversal

Posted by deepcore under exploit (No Respond)

uc-httpd is an HTTP daemon used by a wide array of IoT devices and is vulnerable to local file inclusion and directory traversal bugs.

PCMAN FTP Server 2.0.7 ACCT Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability found in the ACCT command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.

PCMAN FTP Server 2.0.7 GET Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability found in the GET command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.

PCMAN FTP Server 2.0.7 NLST Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability found in the NLST command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.