Subscribe via feed.
Archive for December, 2017

Trend Micro Smart Protection Server 3.2 XSS / Access Control / Disclosure

Posted by deepcore under exploit (No Respond)

Trend Micro Smart Protection Server version 3.2 suffers from access control bypass, cross site scripting, information disclosure, and various other vulnerabilities.

Online Hotel Booking System Pro 1.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Hotel Booking System Pro version 1.3 suffers from a cross site scripting vulnerability.

phpMars 1.0.9 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

phpMars version 1.0.9 suffers from a cross site scripting vulnerability.

Roommate And Real Estate Listing Classified Response 1.0 XSS

Posted by deepcore under exploit (No Respond)

Roommate and Real Estate Listing Classified Response version 1.0 suffers from a cross site scripting vulnerability.

Joomla JB Bus 2.3.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla JB Bus extension version 2.3.0 suffers from a remote SQL injection vulnerability.

Joomla JB Tour Booking 2.2.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla JB Tour Booking extension 2.2.2 suffers from a remote SQL injection vulnerability.

eBPF Arbitrary Read/Write Via Incorrect Range Tracking

Posted by deepcore under exploit (No Respond)

eBPF suffers from an arbitrary read and write vulnerability via incorrect range tracking.

Oracle MySQL UDF Payload Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module creates and enables a custom UDF (user defined function) on the target host via the SELECT … into DUMPFILE method of binary injection. On default Microsoft Windows installations of MySQL versions 5.5.9 and below, directory write permissions not enforced, and the MySQL service runs as LocalSystem. NOTE: This Metasploit module will leave […]

http://division5.immigration.go.th/README.txt

Posted by deepcore under defacement (No Respond)

http://division5.immigration.go.th/README.txt notified by Iran Security Team

Tags:

Netis-WF2419 HTML Injection

Posted by deepcore under exploit (No Respond)

Netis-WF2419 version 2.2.36123 suffers from an html injection issue.