Subscribe via feed.
Archive for May, 2017

http://www.mhkpeo.go.th/menu-1.html

Posted by deepcore under defacement (No Respond)

http://www.mhkpeo.go.th/menu-1.html notified by KATENBAD

Tags:

WordPress Core 4.6 Unauthenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

WordPress (core) 4.6 suffers from an unauthenticated remote code execution condition via an exploitable version of PHPMailer built-in to WordPress code. Exploitation details provided.

http://www.huayton.go.th

Posted by deepcore under defacement (No Respond)

http://www.huayton.go.th notified by Dr.AFN[D]ENA

Tags:

Atlassian SourceTree 2.5c Client URL Handler Command Injection

Posted by deepcore under Apple (No Respond)

Atlassian SourceTree Client version 2.5c and prior contain a client URL handler command injection vulnerability that allows attackers to execute specially crafted sourcetree:// commands with arbitrary arguments on multiple platforms.

Tags: , ,

Mura CMS 7.0.6967 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Mura CMS version 7.0.6967 suffers from cross site scripting vulnerabilities.

Microsoft Internet Explorer 111 CMarkup::DestroySplayTree Use-After-Free

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer 11 suffers from a CMarkup::DestroySplayTree use-after-free vulnerability.

Zenario 7.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Zenario version 7.6 suffers from a delete persistent cross site scripting vulnerability.

Zenario 7.6 Persistent Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Zenario version 7.6 suffers from a persistent cross site scripting vulnerability.

Icecream 4.53 / Pro Privilege Escalation

Posted by deepcore under exploit (No Respond)

Icecream versions 4.53 and Pro suffer from a file permission privilege escalation vulnerability.

Super File Explorer 1.0.1 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Super File Explorer version 1.0.1 suffers from a remote file upload vulnerability.