Subscribe via feed.
Archive for August, 2017

Advantech SUSIAccess 3.0 Directory Traversal / Information Disclosure

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an information disclosure vulnerability found in Advantech SUSIAccess versions 3.0 and below. The vulnerability is triggered when sending a GET request to the server with a series of dot dot slashes (../) in the file parameter.

macOS / iOS xpc_data Objects Sandbox Escapes

Posted by deepcore under exploit (No Respond)

macOS and iOS sandbox escapes and privilege escalation vulnerabilities exist due to unexpected shared memory-backed xpc_data objects.

Advantech SUSIAccess 3.0 File Upload

Posted by deepcore under exploit (No Respond)

Advantech SUSIAccess versions 3.0 and below suffers from a RecoveryMgmt file upload vulnerability.

Nitro Pro PDF Reader 11.0.3.173 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unsafe Javascript API implemented in Nitro and Nitro Pro PDF Reader version 11. The saveAs() Javascript API function allows for writing arbitrary files to the file system. Additionally, the launchURL() function allows an attacker to execute local files on the file system and bypass the security dialog Note: This is […]

[local] Dashlane – DLL Hijacking

Posted by deepcore under Security (No Respond)

Dashlane – DLL Hijacking

Tags: ,

http://reo09.mnre.go.th/reo09/admin/question/

Posted by deepcore under defacement (No Respond)

http://reo09.mnre.go.th/reo09/admin/question/ notified by Mr. DellatioNx196

Tags:

GNU libiberty Buffer Overflow

Posted by deepcore under exploit (No Respond)

GNU libiberty suffers from a buffer overflow vulnerability.

FreeIPA 2.213 Session Hijacking

Posted by deepcore under exploit (No Respond)

FreeIPA version 2.213 suffers from a session hijacking vulnerability.

Friends In War Make Or Break 1.7 Password Change

Posted by deepcore under exploit (No Respond)

Friends in War Make or Break version 1.7 suffers from an unauthenticated administrative password change vulnerability.

Friends In War Make Or Break 1.7 SQL Injection

Posted by deepcore under exploit (No Respond)

Friends in War Make or Break version 1.7 suffers from a remote SQL injection vulnerability.