Subscribe via feed.
Archive for June, 2017

MyBB 1.8.12 Stored XSS / File Enumeration

Posted by deepcore under exploit (No Respond)

MyBB versions 1.8.12 and prior is vulnerable to a cross site scripting bug which can allow a moderator to take over an administrator’s account and upload a webshell, or perform file enumeration in the instances where it is not possible to spawn a shell.

Atlassian Confluence 6.1.1 Access Restriction Bypass

Posted by deepcore under exploit (No Respond)

Atlassian Confluence versions 4.3.0 through 6.1.1 suffers from an access restriction bypass vulnerability.

LG AVI Stream Parsing Missing Bounds-Checking

Posted by deepcore under exploit (No Respond)

LG suffers from missing bounds-checking in AVI stream parsing.

LG CAVIFileParser::Destroy Out-Of-Bounds Heap Read

Posted by deepcore under exploit (No Respond)

LG suffers from an out-of-bounds read in CAVIFileParser::Destroy resulting in an invalid free.

LG ASFParser::ParseHeaderExtensionObjects Missing Bounds Check

Posted by deepcore under exploit (No Respond)

LG has a memcpy in ASFParser::ParseHeaderExtensionObjects that does not check that the size of the copy is smaller than the size of the source buffer, resulting in an out-of-bounds heap read.

Disk Pulse 9.7.26 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Disk Pulse version 9.7.26 suffers from an add directory local buffer overflow vulnerability.

http://ict.nst2.go.th/web1/file_editor/AmoHassan.txt

Posted by deepcore under defacement (No Respond)

http://ict.nst2.go.th/web1/file_editor/AmoHassan.txt notified by ashiyane digital security team

Tags:

http://person.nst2.go.th/web1/file_editor/AmoHassan.txt

Posted by deepcore under defacement (No Respond)

http://person.nst2.go.th/web1/file_editor/AmoHassan.txt notified by ashiyane digital security team

Tags:

http://audit.nst2.go.th/web1/file_editor/AmoHassan.txt

Posted by deepcore under defacement (No Respond)

http://audit.nst2.go.th/web1/file_editor/AmoHassan.txt notified by ashiyane digital security team

Tags:

http://general.nst2.go.th/web1/file_editor/AmoHassan.txt

Posted by deepcore under defacement (No Respond)

http://general.nst2.go.th/web1/file_editor/AmoHassan.txt notified by ashiyane digital security team

Tags: