Subscribe via feed.
Archive for June, 2017

Sitecore 7.1 / 7.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sitecore versions 7.1 and 7.2 suffer from a cross site scripting vulnerability.

Vaadin 7.7.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Vaadin version 7.7.6 suffers from a cross site scripting vulnerability.

PayPal Marketing User Enumeration

Posted by deepcore under exploit (No Respond)

PayPal’s Marketing Online Service suffers from a user enumeration vulnerability.

Blackcat CMS 1.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Blackcat CMS version 1.2 suffers from a cross site scripting vulnerability.

SimpleRisk 20170416-001 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SimpleRisk version 20170416-001 suffers from multiple cross site scripting vulnerabilities.

Cisco Prime Infrastructure 3.1.6 XXE Injection / XSS / LFD / SQL Injection

Posted by deepcore under exploit (No Respond)

Cisco Prime Infrastructure versions 1.1 through 3.1.6 suffer from cross site scripting, XML external entity injection, file disclosure, and remote SQL injection vulnerabilities.

WordPress FormCraft Basic 1.0.5 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress FormCraft Basic plugin version 1.0.5 suffers from multiple remote SQL injection vulnerabilities.

Eltek SmartPack Backdoor Account

Posted by deepcore under exploit (No Respond)

Eltek SmartPack has backdoor accounts that are disclosed via some json files.

Netgear DGN2200 dnslookup.cgi Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in NETGEAR DGN2200v1/v2/v3/v4 routers by sending a specially crafted post request with valid login details.

Symantec Messaging Gateway Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits the command injection vulnerability of Symantec Messaging Gateway product. An authenticated user can execute a terminal command under the context of the web server user which is root. backupNow.do endpoint takes several user inputs and then pass them to the internal service which is responsible for executing operating system command. One […]