Subscribe via feed.
Archive for April, 2017

PCMAN FTP Server 2.0.7 MKD Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability found in the MKD command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.

WordPress BestWebSoft XSS / CSRF

Posted by deepcore under exploit (No Respond)

53+ WordPress plugins by BestWebSoft suffer from cross site scripting and cross site request forgery vulnerabilities.

Magento 2.1.6 Shell Upload / Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Magento versions 2.1.6 and below suffers from cross site request forgery and shell upload vulnerabilities.

Solaris x86 / SPARC EXTREMEPARR dtappgather Privilege Escalation

Posted by deepcore under exploit (No Respond)

Solaris versions 7 through 11 on both x86 and SPARC suffer from an EXTREMEPARR dtappgather local privilege escalation vulnerability.

Cisco Catalyst 2960 IOS 12.2(55)SE11 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Cisco Catalyst 2960 with IOS version 12.2(55)SE11 ROCEM remote code execution exploit.

Adobe Creative Cloud Desktop Application 4.0.0.185 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Adobe Creative Cloud Desktop Application versions 4.0.0.185 and below suffers from a privilege escalation vulnerability.

Nintendo 3DS DNS Client Resolver Predictable TXID

Posted by deepcore under exploit (No Respond)

The Nintendo 3DS DNS client resolver library uses a predictable (incremented) TXID allowing for the spoofing of responses.

FAQ Script 3.1.3 SQL Injection

Posted by deepcore under exploit (No Respond)

FAQ Script version 3.1.3 suffers from a remote SQL injection vulnerability.

Microsoft Office OneNote 2007 DLL Hijacking

Posted by deepcore under exploit (No Respond)

Microsoft Office OneNote 2007 suffers from a dll hijacking vulnerability.

Classified Portal Software 5.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Classified Portal Software version 5.1 suffers from a remote SQL injection vulnerability.