Subscribe via feed.
Archive for May, 2017

WordPress Tracking Code Manager 1.11.1 XSS / DoS

Posted by deepcore under exploit (No Respond)

WordPress Tracking Code Manager plugin versions 1.11.1 and below suffer from cross site scripting and denial of service vulnerabilities.

WordPress User Access Manager 1.2.14 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress User Access Manager plugin versions 1.2.14 and below suffer from a cross site scripting vulnerability.

Linux Kernel SO_SNDBUFFORCE / SO_RCVBUFFORCE Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Linux kernel versions 3.11 through 4.8 O_SNDBUFFORCE and SO_RCVBUFFORCE local privilege escalation exploit.

Vanilla Forums 2.3 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Vanilla Forums versions 2.3 and below remote code execution exploit.

Linux Kernel 3.x usb-midi Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Linux kernel version 3.x (Ubuntu 14.04 / Mint 17.3 / Fedora 22) double-free usb-midi SMEP local privilege escalation exploit.

OpenVPN 2.4.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

OpenVPN version 2.4.0 suffers from an unauthenticated denial of service vulnerability.

Trashbilling.com / Trashflow 3.0 XSS / SQL Injection

Posted by deepcore under exploit (No Respond)

Trashbilling.com suffered from account enumeration, cross site scripting, denial of service, and remote SQL injection vulnerabilities. Trashflow 3.0 suffers from denial of service and hard-coded credential vulnerabilities.

Google API PHP Client 2.1.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

google-api-php-client versions 2.1.3 and below suffer from multiple cross site scripting vulnerabilities.

CMS Made Simple 2.1.6 Code Execution / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CMS Made Simple version 2.1.6 suffers from code execution and cross site scripting vulnerabilities.

EnCase Forensic Imager 7.10 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Guidance Software EnCase Forensic Imager versions 7.10 and below suffer from a stack-based buffer overflow vulnerability.