Subscribe via feed.
Archive for September, 2017

EE 4GEE Wireless Router EE60_00_05.00_25 XSS / CSRF / Disclosure

Posted by deepcore under exploit (No Respond)

EE 4GEE wireless router version EE60_00_05.00_25 suffers from cross site request forgery, cross site scripting, and information disclosure vulnerabilities.

Roteador Wirelsss Intelbras WRN150 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Roteador Wireless Intelbras WRN150 router suffers from a cross site scripting vulnerability.

CMS Showcase 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CMS Showcase version 1.0 suffers from multiple cross site scripting vulnerabilities.

WordPress Training Membership 1.0.8 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Fitness Trainer – Training Membership plugin versions 1.0.8 and below suffer from a cross site scripting vulnerability.

D-Link 850L XSS / Backdoor / Code Execution

Posted by deepcore under exploit (No Respond)

D-Link 850L suffers from cross site scripting, access bypass, backdoor, bruteforcing, information disclosure, remote code execution, and denial of service vulnerabilities. Basically, do not use this device unless you want to analyze it to see how not to design something.

Docker Daemon Unprotected TCP Socket

Posted by deepcore under exploit (No Respond)

Utilizing Docker via unprotected tcp socket (2375/tcp, maybe 2376/tcp with tls but without tls-auth), an attacker can create a Docker container with the ‘/’ path mounted with read/write permissions on the host server that is running the Docker container. As the Docker container executes command as uid 0 it is honored by the host operating […]

http://www.bandarbangovths.gov.bd

Posted by deepcore under defacement (No Respond)

http://www.bandarbangovths.gov.bd notified by Kashif HaxOr

Tags:

http://plutaluang.go.th/media/media/css/b0x.txt

Posted by deepcore under defacement (No Respond)

http://plutaluang.go.th/media/media/css/b0x.txt notified by LUN4T1C0

Tags:

http://doc.deqp.go.th/b0x.txt

Posted by deepcore under defacement (No Respond)

http://doc.deqp.go.th/b0x.txt notified by LUN4T1C0

Tags:

Subrion CMS 4.1.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Subrion CMS version 4.1.5 suffers from a cross site scripting vulnerability.