Subscribe via feed.
Archive for May, 2017

WordPress FancyProductDesigner 3.4.2 Stored XSS

Posted by deepcore under exploit (No Respond)

WordPress FancyProductDesigner plugin versions prior to 3.4.2 suffer from a persistent cross site scripting vulnerability due to improper sanitization, allowing malicious .svg file uploads.

CMS Made Simple Babel Module 0.3.3 Open Redirect / Content Forgery

Posted by deepcore under exploit (No Respond)

CMS Made Simple Babel Module versions prior to 0.3.3 suffer from multiple open redirection and content forgery vulnerabilities.

osCommerce Error-based SQL Injection

Posted by deepcore under exploit (No Respond)

TemplateMonster osCommerce prior to version 2.3x suffers from an error-based SQL injection vulnerability.

Zomato Bug Bounty – Account Take Over Vulnerability

Posted by deepcore under exploit (No Respond)

Hola VPN v1.34 – Privilege Escalation Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered an privilege escalation vulnerability in the official Hola VP…

http://webhost.cpd.go.th

Posted by deepcore under defacement (No Respond)

http://webhost.cpd.go.th notified by AnoaGhost

Tags:

Stanford University (MBC) – SQL Injection Web Vulnerability

Posted by deepcore under exploit (No Respond)

The independent security researcher discovered sql-injection vulnerability in the official Stanford University MBC onli…

Joomla com_tag v1.7.6 – (tag) SQL Injection Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory partner team discovered a sql-injection vulnerability in the official Joomla CMS…

Icecream v4.53 & Pro – File Permission Privilege Escalatio

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered an insecure file permission privilege escalation vulnerabilit…

Emby MediaServer 3.2.5 Boolean-based Blind SQL Injection

Posted by deepcore under exploit (No Respond)

Emby MediaServer version 3.2.5 suffers from a blind SQL injection vulnerability. Input passed via the GET parameter ‘MediaTypes’ is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.