Subscribe via feed.
Archive for July, 2017

[remote] McAfee Security Scan Plus – Remote Command Execution

Posted by deepcore under Security (No Respond)

McAfee Security Scan Plus – Remote Command Execution

Tags: ,

http://www.natub.go.th/content/

Posted by deepcore under defacement (No Respond)

http://www.natub.go.th/content/ notified by @Df Brazil Hack Team

Tags:

WordPress Ultimate Affiliate Pro 3.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Ultimate Affiliate Pro plugin versions 3.6 and below suffer from a persistent cross site scripting vulnerability.

WordPress FormCraft Form Builder 3.2.31 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress FormCraft Premium WordPress Form Builder versions 3.2.31 and below suffer from a persistent cross site scripting vulnerability.

http://www.thabo-mu.go.th

Posted by deepcore under defacement (No Respond)

http://www.thabo-mu.go.th notified by D4RKM491C

Tags:

http://www.bandonglocal.go.th

Posted by deepcore under defacement (No Respond)

http://www.bandonglocal.go.th notified by D4RKM491C

Tags:

http://suphan.go.th

Posted by deepcore under defacement (No Respond)

http://suphan.go.th notified by D4RKM491C

Tags:

REDDOXX Appliance Session Identifier Extraction

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered an information disclosure vulnerability in the REDDOXX appliance software, which allows unauthenticated attackers to extract valid session IDs. Affected versions include build 2032 and 2.0.625.

REDDOXX Appliance RdxEngine-API File Disclosure

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered an arbitrary file disclosure vulnerability in the REDDOXX appliance software, which allows unauthenticated attackers to list directory contents and download arbitrary files from the affected system with root permissions. Affected versions include build 2032 and 2.0.625.

REDDOXX Appliance Cross Site Scripting

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a cross site scripting (XSS) vulnerability in the REDDOXX appliance software, which allows attackers to inject arbitrary JavaScript code via a crafted URL. Affected versions include build 2032 and 2.0.625.