Subscribe via feed.
Archive for January, 2018

Tumder 2.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Tumder version 2.1 suffers from a remote SQL injection vulnerability.

Oracle Financial Services Analytical Applications 7.3.5.x / 8.0.x XXE Injection / XSS

Posted by deepcore under exploit (No Respond)

Oracle Financial Services Analytical Applications versions 7.3.5.x and 8.0.x suffer from XML external entity injection and cross site scripting vulnerabilities.

Zechat 1.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Zechat version 1.5 suffers from a remote SQL injection vulnerability.

Wchat 1.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Wchat version 1.5 suffers from a remote SQL injection vulnerability.

SugarCRM Community Edition 6.5.26 SQL Injection

Posted by deepcore under exploit (No Respond)

SugarCRM Community Edition versions 6.5.26 and below suffer from multiple remote SQL injection vulnerabilities.

GoAhead Web Server LD_PRELOAD Arbitrary Module Load

Posted by deepcore under exploit (No Respond)

This Metasploit module triggers an arbitrary shared library load vulnerability in GoAhead web server versions between 2.5 and that have the CGI module enabled.

Kaltura Remote PHP Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an Object Injection vulnerability in Kaltura. By exploiting this vulnerability, unauthenticated users can execute arbitrary code under the context of the web server user. Kaltura makes use of a hard-coded cookie secret which allows to sign arbitrary cookie data. After passing this signature check, the base64- decoded data is passed to […]

Sync Breeze Enterprise 9.5.16 Import Command Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in Sync Breeze Enterprise 9.5.16 by using the import command option to import a specially crafted xml file.

Oracle VirtualBox Guest To Host Escape

Posted by deepcore under exploit (No Respond)

Oracle VirtualBox versions prior to 5.1.30 and 5.2-rc1 suffer from a guest to host escape vulnerability.

MixPad 5.00 Buffer Overflow

Posted by deepcore under exploit (No Respond)

MixPad version 5.00 suffers from a buffer overflow vulnerability.