Subscribe via feed.
Archive for October, 2017

PHP Melody 2.6.1 SQL Injection

Posted by deepcore under exploit (No Respond)

PHP Melody version 2.6.1 suffers from a remote SQL injection vulnerability.

Infoblox NetMRI 7.1.4 Shell Escape / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Infoblox NetMRI versions 7.1.2 through 7.1.4 suffer from administration shell escape and privilege escalation vulnerabilities.

Infoblox NetMRI VM-AD30-5C6CE Factory Reset Persistence

Posted by deepcore under exploit (No Respond)

Infoblox NetMRI version VM-AD30-5C6CE suffers from an administration shell factory reset persistence vulnerability.

Sonicwall WXA5000 1.3.2-10-30 Console Jail Escape / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Sonicwall WXA5000 version 1.3.2-10-30 suffers from console jail escape and privilege escalation vulnerabilities.

Sophos UTM 9 loginuser Privilege Escalation Via Insecure Directory Permissions

Posted by deepcore under exploit (No Respond)

Sophos UTM 9 suffers from a loginuser privilege escalation vulnerability via insecure directory permissions. Version 9.410 is affected.

Sophos UTM 9 Management Appplication Local File Inclusion

Posted by deepcore under exploit (No Respond)

Sophos UTM 9 suffers from a local file inclusion vulnerability. Version 9.410 is affected.

[remote] Netgear DGN1000 1.1.00.48 – Setup.cgi Unauthenticated Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Netgear DGN1000 1.1.00.48 – Setup.cgi Unauthenticated Remote Code Execution (Metasploit)

Tags: ,

[webapps] KeystoneJS 4.0.0-beta.5 – CSV Excel Macro Injection

Posted by deepcore under Security (No Respond)

KeystoneJS 4.0.0-beta.5 – CSV Excel Macro Injection

Tags: ,

[webapps] KeystoneJS 4.0.0-beta.5 – Cross-Site Scripting

Posted by deepcore under Security (No Respond)

KeystoneJS 4.0.0-beta.5 – Cross-Site Scripting

Tags: ,

Apple Support iOS Application 1.1.1 Unencrypted Third Party Analytics

Posted by deepcore under Apple (No Respond)

Apple Support iOS application versions 1.1.1 and below send potentially sensitive information such as mobile carrier, install date and time, number of app launches, device model, iOS version and screen resolution, unencrypted to a third party site (Adobe Marketing Cloud).

Tags: , ,