Subscribe via feed.
Archive for August, 2017

KATHREIN UFSconnect 916 / 906 DoS / Unauthenticated Actions

Posted by deepcore under exploit (No Respond)

KATHREIN UFSconnect 916 and 906 with firmware version 2.23 build 224 suffer from denial of service and unauthenticated access vulnerabilities.

Ubiquiti Networks UniFi Cloud Key Command Injection / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Ubiquiti Networks UniFi Cloud Key with firmware versions 0.5.9 and 0.6.0 suffer from weak crypto, privilege escalation, and command injection vulnerabilities.

TYPO3 Formhandler 2.4.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

TYPO3 Formhandler version 2.4.0 suffers from a cross site scripting vulnerability.

Vehicle Workshop SQL Injection

Posted by deepcore under exploit (No Respond)

Vehicle Workshop suffers from a remote SQL injection vulnerability.

FortiOS 5.6.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

FortiOS versions 5.6.0 and below suffer from multiple cross site scripting vulnerabilities.

Flash Slideshow Maker Professional XSS / Content Forgery / Redirect

Posted by deepcore under exploit (No Respond)

Flash Slideshow Maker Professional suffers from content forgery, cross site scripting, and unvalidated redirection vulnerabilities.

Jenkins Java Deserialization

Posted by deepcore under exploit (No Respond)

Jenkins versions prior to 1.650 suffer from a java deserialization vulnerability.

WordPress Logosware Suite Uploader 1.1.6 File Upload

Posted by deepcore under exploit (No Respond)

WordPress Logosware Suite Uploader plugin version 1.1.6 suffers from a remote file upload vulnerability.

DiskBoss Enterprise 8.2.14 Buffer Overflow

Posted by deepcore under exploit (No Respond)

DiskBoss Enterprise version 8.2.14 suffers from a buffer overflow vulnerability.

Links 2.14 Denial Of Service

Posted by deepcore under exploit (No Respond)

The put_chars function in html_r.c in Links version 2.14 can cause a denial of service (buffer over-read) via a crafted html file.