Subscribe via feed.
Archive for August, 2017

Posty 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Posty version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Easy RM RMVB To DVD Burner 1.8.11 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Easy RM RMVB to DVD Burner version 18.11 buffer overflow exploit.

Matrimony 2.7 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Matrimony version 2.7 suffers from a cross site request forgery vulnerability.

NethServer 7.3.1611 Upload.json CSRF Script Insertion

Posted by deepcore under exploit (No Respond)

NethServer version 7.3.1611 suffers from a cross site request forgery script insertion vulnerability in Upload.json.

NethServer 7.3.1611 CSRF Create User / Enable SSH Access

Posted by deepcore under exploit (No Respond)

NethServer version 7.3.1611 suffers from a cross site request forgery vulnerability that allows you to create a user and enable SSH access.

Microsoft Windows PPL Process Injection Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from an issue where it is possible to inject code into a PPL protected process by hijacking COM objects leading to accessing PPL processes such as Lsa and AntiMalware from an administrator.

QNAP Transcode Server Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote command injection vulnerability in QNAP NAS devices. The transcoding server listens on port 9251 by default and is vulnerable to command injection using the ‘rmfile’ command. This Metasploit module was tested successfully on a QNAP TS-431 with firmware version 4.3.3.0262 (20170727).

The Next Generation Of Genealogy Sitebuilding SQL Injection

Posted by deepcore under exploit (No Respond)

The Next Generation of Genealogy Sitebuilding versions prior to 11.1.1 suffer from a remote SQL injection vulnerability.

Apple iOS Sandbox Escape

Posted by deepcore under Apple (No Respond)

Apple iOS versions prior to 10.3.1 kernel exploit that demonstrates a sandbox escape.

Tags: , ,

http://www.tranghos.go.th/media/ind3x.html

Posted by deepcore under defacement (No Respond)

http://www.tranghos.go.th/media/ind3x.html notified by MOLOTOV-Dz

Tags: