Subscribe via feed.
Archive for September, 2017

Microsoft Edge DuplicateHandle ACG Bypass

Posted by deepcore under exploit (No Respond)

ACG (Arbitrary Code Guard) in Microsoft Edge is bypassable. The bypass has been tested on Microsoft Edge 40.15063.0.0 running on Windows 10 Enterprise 64-bit with Creators Update (Version 1703, OS build 15063.413).

Mako Server SSRF / Disclosure / Code Execution

Posted by deepcore under exploit (No Respond)

Mako Web Server suffers from file disclosure, remote command execution, and server-side request forgery vulnerabilities.

IBM Infosphere Information Server / Datastage 11.5 Command Execution / Bypass

Posted by deepcore under exploit (No Respond)

IBM Infosphere Information Server / Datastage versions 9.1, 11.3, and 11.5 (including Cloud version 11.5) suffer from bypass, XML external entity injection, DLL side loading, and various other vulnerabilities.

VLC Media Player iOS App 2.7.8 File Disclosure

Posted by deepcore under exploit (No Respond)

VLC Media Player iOS application version 2.7.8 suffers from a file disclosure vulnerability.

Ubiquiti Networks UniFi Cloud Key Command Injection

Posted by deepcore under exploit (No Respond)

Ubiquiti Networks UniFi Cloud Key wwith firmware versions 0.6.4 and below suffer from an authenticated command injection vulnerability.

SilverStrip CMS 3.5.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SilverStripe CMS versions 3.5.3 and below suffer from a persistent cross site scripting vulnerability.

osTicket 1.10 SQL Injection

Posted by deepcore under exploit (No Respond)

osTicket version 1.10 suffers from a remote SQL injection vulnerability.

FoodStar Swiggy Clone Script 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

FoodStar Swiggy Clone Script version 1.0 suffers from a remote SQL injection vulnerability.

PHP Dashboards NEW 4.4 Arbitrary File Read

Posted by deepcore under exploit (No Respond)

PHP Dashboards NEW version 4.4 suffers from an arbitrary file read vulnerability.

Jungo DriverWizard WinDriver 12.4.0 Overflow

Posted by deepcore under exploit (No Respond)

Jungo DriverWizard WinDriver versions 12.4.0 and below suffer from a kernel pool overflow vulnerability.