Subscribe via feed.
Archive for April, 2017

Social Directory Script 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Social Directory Script version 2.0 suffers from a remote SQL injection vulnerability.

Adobe XML Injection File Content Disclosure

Posted by deepcore under exploit (No Respond)

Multiple Adobe products suffer from an XML injection file content disclosure vulnerability.

Quest Privilege Manager 6.0.0 Arbitrary File Write

Posted by deepcore under exploit (No Respond)

Quest Privilege Manager version 6.0.0 suffers from an arbitrary file write vulnerability.

s9y Serendipity Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

s9y Serendipity versions prior to 2.0.5 suffer from a cross site request forgery vulnerability.

MyBB Cross Site Scripting

Posted by deepcore under exploit (No Respond)

MyBB versions prior to 1.8.11 suffers from a cross site scripting vulnerability.

MyBB Directory Traversal

Posted by deepcore under exploit (No Respond)

MyBB versions prior to 1.8.11 suffer from a directory traversal vulnerability.

MATESO GmbH Password Safe And Repository Enterprise 7.4.4 Build 2247 SQL Injection

Posted by deepcore under exploit (No Respond)

MATESO GmbH Password Safe and Repository Enterprise version 7.4.4 build 2247 suffers from a remote SQL injection vulnerability.

MATESO GmbH Password Safe And Repository Enterprise 7.4.4 Build 2247 Credential Management

Posted by deepcore under exploit (No Respond)

MATESO GmbH Password Safe and Repository Enterprise 7.4.4 build 2247 suffers from poor credential management using unsalted MD5 hashes.

Proxifier 2.18 Privilege Escalation / Code Execution

Posted by deepcore under exploit (No Respond)

Proxifier versions 2.18 and below ships with a KLoader binary which it installs suid root the first time Proxifier is run. This binary serves a single purpose which is to load and unload Proxifier’s kernel extension. Unfortunately it does this by taking the first parameter passed to it on the commandline without any sanitisation and […]

Brother MFC-J6520DW Password Change Authentication Bypass

Posted by deepcore under exploit (No Respond)

Brother MFC-J6520DW suffers from a password changing authentication bypass vulnerability.