Subscribe via feed.
Archive for October, 2017

[remote] Rancher Server – Docker Daemon Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Rancher Server – Docker Daemon Code Execution (Metasploit)

Tags: ,

Magento Cross Site Requst Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

During a security audit of Magento Community Edition / Open Source and Commerce, cross site request forgery and stored cross site scripting vulnerabilities were discovered that could lead to administrator account takeover, putting the website customers and their payment information at risk. Versions affected include Magento CE 1 prior to 1.9.3.6, Magento Commerce prior to […]

SmartBear SoapUI 5.3.0 Remote Code Execution Via Deserialization

Posted by deepcore under exploit (No Respond)

SmartBear SoapUI version 5.3.0 suffers from a remote code execution vulnerability via deserialization.

Unitrends UEB 9.1 bpserverd Remote Command Execution

Posted by deepcore under exploit (No Respond)

Unitrends UEB version 9.1 bpserverd remote command execution exploit.

Lansweeper 6.0.0.63 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Lansweeper version 6.0.0.63 suffers from a cross site scripting vulnerability.

Microsoft Windows 10 x64 RS2 win32kfull!bFill Overflow

Posted by deepcore under exploit (No Respond)

This is a collection of exploits for the recently-patched win32kfull!bFill vulnerability. Executing the Palette or Bitmap exploit will give you SYSTEM privileges on the affected system. The exploits should work fine on Windows 10 x64 with Creators Update, build 15063.540 (latest version of Win10 before the release of Microsoft’s September Updates).

WordPress 4.8.2 Activation Key Failed Expiry

Posted by deepcore under exploit (No Respond)

WordPress version 4.8.2 fails to have an expiration mechanism tied to activation keys allowing for eternal use.

Lansweeper 6.0.100.29 XXE Injection

Posted by deepcore under exploit (No Respond)

Lansweeper version 6.0.100.29 suffers from an XML external entity injection vulnerability.

Metasploit Cross Site Rquest Forgery

Posted by deepcore under exploit (No Respond)

Metasploit Pro, Express, Ultimate, and Community suffer from a cross site request forgery vulnerability.

OrientDB 2.2.x Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module leverages a privilege escalation on OrientDB to execute unsandboxed OS commands. All versions from 2.2.2 up to 2.2.22 should be vulnerable.