Subscribe via feed.
Archive for September, 2017

[webapps] Trend Micro OfficeScan 11.0/XG (12.0) – Information Disclosure

Posted by deepcore under Security (No Respond)

Trend Micro OfficeScan 11.0/XG (12.0) – Information Disclosure

Tags: ,

[papers] [eZine] i sh0t the white hat 1

Posted by deepcore under Security (No Respond)

[eZine] i sh0t the white hat 1

Tags: ,

[papers] [eZine] i sh0t the white hat 2

Posted by deepcore under Security (No Respond)

[eZine] i sh0t the white hat 2

Tags: ,

[papers] [eZine] i sh0t the white hat 3

Posted by deepcore under Security (No Respond)

[eZine] i sh0t the white hat 3

Tags: ,

[remote] LAquis SCADA 4.1.0.2385 – Directory Traversal (Metasploit)

Posted by deepcore under Security (No Respond)

LAquis SCADA 4.1.0.2385 – Directory Traversal (Metasploit)

Tags: ,

Kaltura 13.1.0 Code Execution / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Kaltura versions 13.1.0 and below suffer from code execution and cross site scripting vulnerabilities.

BlueBorne BlueTooth Buffer Overflow Proof Of Concept

Posted by deepcore under exploit (No Respond)

BlueBorne BlueTooth buffer overflow proof of concept exploit that causes a denial of service vulnerability on Linux kernels prior to 4.13.1.

Supervisor XML-RPC Authenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in the Supervisor process control software, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. Depending on how supervisord has been configured, this may be root. […]

FLIR Systems FLIR Thermal Camera FC-S/PT Authenticated OS Command Injection

Posted by deepcore under exploit (No Respond)

FLIR FC-S/PT series suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user.

FLIR Systems FLIR Thermal Camera PT-Series (PT-334 200562) Remote Root

Posted by deepcore under exploit (No Respond)

FLIR Camera PT-Series suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exist due to several POST parameters in controllerFlirSystem.php script when calling the execFlirSystem() function not being sanitized when using the shell_exec() PHP function while updating the network settings on the affected device. This allows the attacker to execute arbitrary system commands as […]