Subscribe via feed.
Archive for April, 2017

Oracle PeopleSoft ToolsRelease / ToolsReleaseDB / HCM SSRF

Posted by deepcore under exploit (No Respond)

Oracle PeopleSoft ToolsRelease version 8.55.03, ToolsReleaseDB version 8.55, and HCM version 9.2 suffer from a server-side request forgery vulnerability.

Microsoft Windows ManagementObject Arbitrary .NET Serialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from a ManagementObject arbitrary .NET serialization remote code execution vulnerability.

Microsoft Windows Runtime Broker ClipboardBroker Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from a runtime broker ClipboardBroker privilege escalation vulnerability.

VirtualBox Guest-To-Host Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

VirtualBox suffers from a guest-to-host local privilege escalation vulnerability via broken length handling in slirp copy.

VirtualBox Host User To Host Kernel Privilege Escalation

Posted by deepcore under exploit (No Respond)

VirtualBox suffers from an unprivileged host user to host kernel privilege escalation vulnerability via environment and ioctl.

Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits two vulnerabilities the Trend Micro Threat Discovery Appliance. The first is an authentication bypass vulnerability via a file delete in logoff.cgi which resets the admin password back to ‘admin’ upon a reboot (CVE-2016-7552). The second is a cmd injection flaw using the timezone parameter in the admin_sys_time.cgi interface (CVE-2016-7547).

Microsoft Windows IEETWCollector Arbitrary Directory / File Deletion Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from an IEETWCollector arbitrary directory / file deletion privilege escalation vulnerability.

WebKit operationSpreadGeneric Universal Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WebKit suffers from a universal cross site scripting vulnerability in operationSpreadGeneric.

VirtualBox Unprivilege Host User To Host Kernel Privilege Escalation

Posted by deepcore under exploit (No Respond)

VirtualBox suffers from an unprivileged host user to host kernel privilege escalation via ALSA config.

Microsoft RTF Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft RTF CVE-2017-0199 proof of concept exploit.