Subscribe via feed.
Archive for August, 2017

Disk Pulse Enterprise 9.9.16 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Disk Pulse Enterprise version 9.9.16 suffers from a buffer overflow vulnerability.

IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote PHP code execution vulnerability in IBM OpenAdmin Tool included with IBM Informix versions 11.5, 11.7, and 12.1. The ‘welcomeServer’ SOAP service does not properly validate user input in the ‘new_home_page’ parameter of the ‘saveHomePage’ method allowing arbitrary PHP code to be written to the config.php file. The config.php […]

VMware VDP Known SSH Key

Posted by deepcore under exploit (No Respond)

VMware vSphere Data Protection appliances 5.5.x through 6.1.x contain a known ssh private key for the local user admin who is a sudoer without password.

Windows Escalate UAC Protection Bypass (Via COM Handler Hijack)

Posted by deepcore under exploit (No Respond)

This Metasploit module will bypass Windows UAC by creating COM handler registry entries in the HKCU hive. When certain high integrity processes are loaded, these registry entries are referenced resulting in the process loading user-controlled DLLs. These DLLs contain the payloads that result in elevated sessions. Registry key modifications are cleaned up after payload invocation. […]

http://bangosato.go.th/id.htm

Posted by deepcore under defacement (No Respond)

http://bangosato.go.th/id.htm notified by Mr.DreamX196

Tags:

http://khaokhansong.go.th/id.htm

Posted by deepcore under defacement (No Respond)

http://khaokhansong.go.th/id.htm notified by Mr.DreamX196

Tags:

http://ictsgp.moi.go.th/srs.txt

Posted by deepcore under defacement (No Respond)

http://ictsgp.moi.go.th/srs.txt notified by Syrian Hexor

Tags:

WpJobBoard v4.5.1 – Multiple Cross Site Web Vulnerabilities

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered multiple client-side cross site web vulnerabilties in the WpJ…

PotPlayer 1.7.x – Stack Buffer Overflow Vulnerability

Posted by deepcore under exploit (No Respond)

[local] WebKitGTK 2.1.2 (Ubuntu 14.04) – Heap based Buffer Overflow

Posted by deepcore under Security (No Respond)

WebKitGTK 2.1.2 (Ubuntu 14.04) – Heap based Buffer Overflow

Tags: ,