Subscribe via feed.
Archive for February, 2018

LogicalDOC Enterprise 7.7.4 Post-Auth Command Execution

Posted by deepcore under exploit (No Respond)

LogicalDOC Enterprise version 7.7.4 suffers from a post-authentication command execution vulnerability via binary path manipulation.

CloudMe Sync 1.10.9 Remote Buffer Overflow

Posted by deepcore under exploit (No Respond)

CloudMe Sync versions 1.10.9 and below suffer from an unauthenticated remote buffer overflow vulnerability.

[remote] CloudMe Sync < 1.11.0 – Buffer Overflow

Posted by deepcore under Security (No Respond)

CloudMe Sync < 1.11.0 – Buffer Overflow

Tags: ,

[webapps] TypeSetter CMS 5.1 – 'Host' Header Injection

Posted by deepcore under Security (No Respond)

TypeSetter CMS 5.1 – ‘Host’ Header Injection

Tags: ,

[webapps] TypeSetter CMS 5.1 – Cross-Site Request Forgery

Posted by deepcore under Security (No Respond)

TypeSetter CMS 5.1 – Cross-Site Request Forgery

Tags: ,

[webapps] News Website Script 2.0.4 – 'search' SQL Injection

Posted by deepcore under Security (No Respond)

News Website Script 2.0.4 – ‘search’ SQL Injection

Tags: ,

http://www.omkoi.go.th/readme.htm

Posted by deepcore under defacement (No Respond)

http://www.omkoi.go.th/readme.htm notified by Dijehaji

Tags:

SoapUI 5.3.0 Code Execution

Posted by deepcore under exploit (No Respond)

SoapUI suffers from an arbitrary code execution vulnerability via a maliciously imported project.

Juju-run Agent Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module attempts to gain root privileges on Juju agent systems running the juju-run agent utility. Juju agent systems running agent tools prior to version 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3, provide a UNIX domain socket to manage software (“units”) without setting appropriate permissions, allowing unprivileged local users to execute arbitrary commands […]

[local] glibc – '$ORIGIN' Expansion Privilege Escalation (Metasploit)

Posted by deepcore under Security (No Respond)

glibc – ‘$ORIGIN’ Expansion Privilege Escalation (Metasploit)

Tags: ,