Subscribe via feed.
Archive for January, 2018

Seagate Media Server Arbitrary File / Folder Deletion

Posted by deepcore under exploit (No Respond)

Seagate Media Server on a Seagate Personal Cloud model SRN21C running firmware version 4.3.16.0 suffers from an unauthenticated arbitrary file and folder deletion vulnerability.

D-Link DNS-343 ShareCenter 1.05 Command Injection

Posted by deepcore under exploit (No Respond)

D-Link DNS-343 ShareCenter versions 1.05 and below suffer from a remote command injection vulnerability.

D-Link DNS-325 ShareCenter 1.05B03 Shell Upload / Command Injection

Posted by deepcore under exploit (No Respond)

D-Link DNS-325 ShareCenter versions 1.05B03 and below suffer from remote shell upload and command injection vulnerabilities.

Shibboleth 2 XML Injection

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the shibd service of Shibboleth 2 does not extract SAML attribute values in a robust manner. By inserting XML entities into a SAML response, attackers may truncate attribute values without breaking the document’s signature. This might lead to a complete bypass of authorisation mechanisms. Versions prior to 2.6.1 are affected.

http://www.nonsanga.go.th/web1/file_editor/SeRaVo.txt

Posted by deepcore under defacement (No Respond)

http://www.nonsanga.go.th/web1/file_editor/SeRaVo.txt notified by SeRaVo BlackHaT

Tags:

http://kalasin.nfe.go.th//file_editor/0day.txt

Posted by deepcore under defacement (No Respond)

http://kalasin.nfe.go.th//file_editor/0day.txt notified by Danger BoY

Tags:

Photo Vault v1.2 iOS – Insecure Authentication Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability labortory core research team discovered a insecure authentication issue in the official …

Zenario v7.6 CMS – SQL Injection Web Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a remote sql-injection vulnerability in the official Zenario …

Oracle AgileExpress v9.0 – Privilege Escalation Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a local privilege escalation vulnerability in the Oracle Agil…

[local] glibc – 'getcwd()' Local Privilege Escalation

Posted by deepcore under Security (No Respond)

glibc – ‘getcwd()’ Local Privilege Escalation

Tags: ,