Subscribe via feed.
Archive for May, 2017

Dolibarr 4.0.4 SQL Injection / XSS / Weaknesses

Posted by deepcore under exploit (No Respond)

Dolibarr version 4.0.4 suffers from cross site scripting, weak hashing, weak password change, and remote SQL injection vulnerabilities.

SAP SAPCAR 721.510 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Core Security Technologies Advisory – SAP distributes software and packages using an archive program called SAPCAR. This program uses a custom archive file format. A memory corruption vulnerability was found in the parsing of specially crafted archive files, that could lead to local code execution scenarios. Version 721.510 is affected.

Microsoft MsMpEng UIF Decoder Denial Of Service

Posted by deepcore under exploit (No Respond)

Microsoft MsMpEng suffers from an issue where the UIF decoder will spin forever processing sparse blocks.

FreeTDS Denial Of Service

Posted by deepcore under exploit (No Respond)

This archive contains numerous TDS streams that cause segmentation faults in the FreeTDS library. The ‘tsql’ binary was used for the fuzzing, so these most likely only affect client-side functionality. These have been resolved on master and the 1.0 branch.

BanManager WebUI 1.5.8 Code Injection / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

BanManager WebUI version 1.5.8 suffers from PHP code injection and cross site scripting vulnerabilities.

Gongwalker API Manager 1.1 Blind SQL Injection

Posted by deepcore under exploit (No Respond)

Gongwalker API Manager version 1.1 suffers from a remote blind SQL injection vulnerability.

Gongwalker API Manager 1.1 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Gongwalker API Manager version 1.1 suffers from cross site request forgery vulnerabilities.

QNAP PhotoStation 5.2.4 / MusicStation 4.8.4 Authentication Bypass

Posted by deepcore under exploit (No Respond)

QNAP PhotoStation version 5.2.4 and MusicStation version 4.8.4 suffer from an authentication bypass vulnerability.

Microsoft IIS WebDav ScStoragePathFromUrl Overflow

Posted by deepcore under exploit (No Respond)

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with “If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016. Original exploit by Zhiniang […]

http://lpa.nfe.go.th

Posted by deepcore under defacement (No Respond)

http://lpa.nfe.go.th notified by AnoaGhost

Tags: