Subscribe via feed.
Archive for January, 2018

Piwigo v2.8.2 & 2.9.2 CMS – Multiple Cross Site Vulnerabilities

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered multiple client-side cross site scripting vulnerabilities in …

Polygonize PC 1.1 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Polygonize PC version 1.1 suffers from a remote command execution vulnerability.

Microsoft Edge Chakra JIT Missing Integer Overflow Check

Posted by deepcore under exploit (No Respond)

Microsoft Edge Chakra JIT suffers from a missing integer overflow check in Lowerer::LowerSetConcatStrMultiItem.

Muviko 1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Muviko version 1.1 suffers from a remote SQL injection vulnerability.

WordPress Events Calendar 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress Events Calendar plugin version 1.0 suffers from a remote SQL injection vulnerability.

Android Hardware Service Manager Arbitrary Service Replacement

Posted by deepcore under exploit (No Respond)

Android hardware service manager suffers from an arbitrary service replacement issue due to getpidcon.

WordPress Service Finder Booking Local File Disclosure

Posted by deepcore under exploit (No Respond)

WordPress Service Finder Booking plugin versions prior to 3.2 suffer from a file disclosure vulnerability.

DiskBoss Enterprise 8.8.16 Buffer Overflow

Posted by deepcore under exploit (No Respond)

DiskBoss Enterprise version 8.8.16 suffers from a buffer overflow vulnerability.

WordPress Download Manager 2.9.60 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WordPress Download Manager plugin version 2.9.60 suffers from a cross site request forgery vulnerability.

Sangoma NetBorder / Vega Session Controller Remote Command Execution

Posted by deepcore under exploit (No Respond)

Sangoma NetBorder / Vega Session Controller versions prior to 2.3.12-80-GA allows remote unauthenticated attackers to execute arbitrary commands via the web interface.