Subscribe via feed.
Archive for December, 2017

Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

The Telesquare SKT LTE SDT-CS3B1 router suffers from an insecure direct object reference vulnerability that leaks information.

Telesquare SKT LTE Router SDT-CS3B1 CSRF / Command Execution

Posted by deepcore under exploit (No Respond)

The Telesquare SKT LTE SDT-CS3B1 router suffers from authenticated arbitrary system command execution. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Sony Playstation 4 4.05 FW Local Kernel Loader

Posted by deepcore under exploit (No Respond)

In this project you will find a full implementation of the “namedobj” kernel exploit for the PlayStation 4 on 4.05. It will allow you to run arbitrary code as kernel in order to allow jailbreaking and kernel-level modifications to the system. This release does not contain any code related to defeating anti-piracy mechanisms or running […]

DotNetNuke DreamSlider 01.01.02 Arbitrary File Download

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated arbitrary file download vulnerability in DotNetNuke DreamSlider versions 01.01.02 and below.

Telesquare SKT LTE Router SDT-CS3B1 Denial Of Service

Posted by deepcore under exploit (No Respond)

The Telesquare SKT LTE SDT-CS3B1 router suffers from a denial of service vulnerability.

Joomla YouBumpit 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla YouBumpit extension version 2.0 suffers from a remote SQL injection vulnerability.

Tripbuddy Travel, Locations, And Events 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Tripbuddy Travel, Locations, and Events version 1.0 suffers from a cross site scripting vulnerability.

GoodTravel Travel And Locations 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

GoodTravel Travel and Locations PHP script and mobile application version 1.0 suffers from a cross site scripting vulnerability.

HP Insight Control For VMware vCenter Server 7.3 Insecure Permissions

Posted by deepcore under exploit (No Respond)

HP Insight Control for VMware vCenter Server version 7.3 allows a low privileged attacker to read sensitive information files, decrypt all configuration server passwords, and gain access to the systems which in turn leads to the compromise of the whole infrastructure.

ALLMediaServer 0.95 Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a stack buffer overflow in ALLMediaServer 0.95. The vulnerability is caused due to a boundary error within the handling of HTTP request.