Subscribe via feed.
Archive for July, 2017

Schneider Electric Pelco VideoXpert Privilege Escalation

Posted by deepcore under exploit (No Respond)

Schneider Electric Pelco VideoXpert is vulnerable to an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the ‘F’ flag (full) for the ‘Users’ group, for several binary files. The service is […]

Schneider Electric Pelco VideoXpert Core Admin Portal Directory Traversal

Posted by deepcore under exploit (No Respond)

Pelco VideoXpert suffers from a directory traversal vulnerability. Exploiting this issue will allow an unauthenticated attacker to view arbitrary files within the context of the web server.

Schneider Electric Pelco VideoXpert Missing Encryption

Posted by deepcore under exploit (No Respond)

Schneider Electric Pelco VideoXpert transmits sensitive data using double Base64 encoding for the Cookie ‘auth_token’ in a communication channel that can be sniffed by unauthorized actors or arbitrarily be read from the vxcore log file directly using directory traversal attack resulting in authentication bypass / session hijacking.

WMI Event Subscription Persistence

Posted by deepcore under exploit (No Respond)

This Metasploit module will create a permanent WMI event subscription to achieve file-less persistence using one of five methods.

http://cbhospital.go.th/1998.gif

Posted by deepcore under defacement (No Respond)

http://cbhospital.go.th/1998.gif notified by MuhmadEmad

Tags:

Microsoft Office 365 Enterprise E3 Insufficient Session Expiration

Posted by deepcore under exploit (No Respond)

Microsoft Office 365 Enterprise E3 suffers from an insufficient session expiration vulnerability.

Firefox 54.0.1 Denial Of Service

Posted by deepcore under exploit (No Respond)

Firefox version 54.0.1 suffers from a denial of service vulnerability.

Yaws 1.91 Unauthenticated Remote File Disclosure

Posted by deepcore under exploit (No Respond)

Yaws version 1.91 suffers from an unauthenticated remote file disclosure vulnerability.

Lepide Auditor Suite Remote Code Execution

Posted by deepcore under exploit (No Respond)

Lepide Auditor Suite suffers from a createdb() web console database injection remote code execution vulnerability.

LibTIFF tif_dirwrite.c Denial Of Service

Posted by deepcore under exploit (No Respond)

LibTIFF suffers from a denial of service vulnerability in tif_dirwrite.c.