Subscribe via feed.
Archive for July, 2017

Dasan Networks GPON ONT WiFi Router H64X Series System Config Download

Posted by deepcore under exploit (No Respond)

Dasan Networks GPON ONT WiFi Router H64X Series suffers from a system configuration download vulnerability.

iSmartAlarm Backend Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

iSmartAlarm Backend suffers from a server-side request forgery vulnerability.

[remote] OrientDB – Code Execution

Posted by deepcore under Security (No Respond)

OrientDB – Code Execution

Tags: ,

Microsoft Windows EternalBlue SMB Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Windows versions 7, 8.1, 2008 R2, 2012 R2, and 2016 R2 EternalBlue SMB remote code execution exploit that leverages the issue noted in MS17-0101.

NfSen 1.3.7 / AlienVault OSSIM 4.3.1 customfnt Command Injection

Posted by deepcore under exploit (No Respond)

NfSen version 1.3.7 and AlienVault OSSIM version 4.3.1 suffer from a customfmt command injection vulnerability.

RaidenHTTPD 2.0.44 User-Agent Cross Site Scripting

Posted by deepcore under exploit (No Respond)

RaidenHTTPD version 2.0.44 suffers from a cross site scripting vulnerability via the user-agent header.

DataTaker DT80 dEX 1.50.012 Sensitive Configuration Exposure

Posted by deepcore under exploit (No Respond)

DataTaker DT80 dEX version 1.50.012 suffers from an information disclosure vulnerability.

ObjectPlanet Opinio 7.6.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ObjectPlanet Opinio versions 7.6.3 and below suffer from a cross site scripting vulnerability.

IBM Informix 12.10 DB-Access Buffer Overflow

Posted by deepcore under exploit (No Respond)

IBM Informix DB-Access utility is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. The vulnerability is triggered by providing an overly long file parameter value inside a LOAD statement, which is used to insert data from an operating-system file into an existing […]

AGFEO Smart Home ES 5xx / 6xx Authentication Bypass / XSS / Hardcoded Credentials

Posted by deepcore under exploit (No Respond)

AGFEO Smart Home ES 5xx / 6xx versions 1.9b and 1.10 suffers from authentication bypass, cross site scripting, and hard-coded private key vulnerabilities.