Subscribe via feed.
Archive for June, 2017

Robert 0.5 CSRF / XSS / Directory Traversal / SQL Injection

Posted by deepcore under exploit (No Respond)

Robert version 0.5 suffers from cross site request forgery, cross site scripting, remote SQL injection, and directory traversal vulnerabilities.

Sophos Cyberoam Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sophos Cyberoam with firmware versions 10.6.4 and below suffer from a cross site scripting vulnerability.

GravCMS Core 1.4.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

GravCMS Core version 1.4.2 suffers from a persistent cross site scripting vulnerability.

Perch CMS 3.0.3 Cross Site Scripting / File Upload

Posted by deepcore under exploit (No Respond)

Perch CMS version 3.0.3 suffers from cross site scripting and remote file upload vulnerabilities.

Xavier 2.4 SQL Injection

Posted by deepcore under exploit (No Respond)

Xavier PHP Login Script and User Management Admin Panel version 2.4 suffers from a remote SQL injection vulnerability.

DC/OS Marathon UI Docker Privilege Escalation

Posted by deepcore under exploit (No Respond)

Utilizing the DCOS Cluster’s Marathon UI, an attacker can create a docker container with the ‘/’ path mounted with read/write permissions on the host server that is running the docker container. As the docker container executes command as uid 0 it is honored by the host operating system allowing the attacker to edit/create files owed […]

Craft CMS 2.6 Cross Site Scripting / File Upload

Posted by deepcore under exploit (No Respond)

Craft CMS version 2.6 suffers from cross site scripting and remote file upload vulnerabilities.

WiMAX CPE Authentication Bypass

Posted by deepcore under exploit (No Respond)

Various WiMAX CPEs are vulnerable to an authentication bypass. An attacker can set arbitrary configuration values without prior authentication. The vulnerability is located in commit2.cgi (implemented in libmtk_httpd_plugin.so).

Windows UAC Protection Bypass (Via FodHelper Registry Key)

Posted by deepcore under exploit (No Respond)

This Metasploit module will bypass Windows 10 UAC by hijacking a special key in the Registry under the current user hive, and inserting a custom command that will get invoked when the Windows fodhelper.exe application is launched. It will spawn a second shell that has the UAC flag turned off. This Metasploit module modifies a […]

http://thailocal.nso.go.th

Posted by deepcore under defacement (No Respond)

http://thailocal.nso.go.th notified by 3needan

Tags: