Subscribe via feed.
Archive for October, 2017

WordPress Ad Widget 2.10.0 Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Ad Widget plugin versions 2.10.0 and below suffer from a local file inclusion vulnerability.

Trend Micro OfficeScan Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits the authentication bypass and command injection vulnerability together. Unauthenticated users can execute a terminal command under the context of the web server user. The specific flaw exists within the management interface, which listens on TCP port 443 by default. The Trend Micro Officescan product has a widget feature which is implemented […]

[local] ASX to MP3 3.1.3.7 – '.m3u' Buffer Overflow

Posted by deepcore under Security (No Respond)

ASX to MP3 3.1.3.7 – ‘.m3u’ Buffer Overflow

Tags: ,

[webapps] Trend Micro InterScan Messaging Security (Virtual Appliance) – Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Trend Micro InterScan Messaging Security (Virtual Appliance) – Remote Code Execution (Metasploit)

Tags: ,

[webapps] Trend Micro OfficeScan 11.0/XG (12.0) – Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Trend Micro OfficeScan 11.0/XG (12.0) – Remote Code Execution (Metasploit)

Tags: ,

PyroBatchFTP 3.17 Buffer Overflow

Posted by deepcore under exploit (No Respond)

PyroBatchFTP version 3.17 suffers from a local buffer overflow vulnerability.

[webapps] Complain Management System – Hard-Coded Credentials / Blind SQL injection

Posted by deepcore under Security (No Respond)

Complain Management System – Hard-Coded Credentials / Blind SQL injection

Tags: ,

Rancher Server Docker Exploit

Posted by deepcore under exploit (No Respond)

Utilizing Rancher Server, an attacker can create a docker container with the ‘/’ path mounted with read/write permissions on the host server that is running the docker container. As the docker container executes command as uid 0 it is honored by the host operating system allowing the attacker to edit/create files owed by root. This […]

[webapps] QNAP HelpDesk < 1.1.12 – SQL Injection

Posted by deepcore under Security (No Respond)

QNAP HelpDesk < 1.1.12 – SQL Injection

Tags: ,

[remote] OrientDB 2.2.2 – 2.2.22 – Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

OrientDB 2.2.2 – 2.2.22 – Remote Code Execution (Metasploit)

Tags: ,