Subscribe via feed.
Archive for February, 2018

Sonatype Nexus Repository Manager OSS/Pro 2.14.5 / 3.7.1 XSS

Posted by deepcore under exploit (No Respond)

Sonatype Nexus Repository Manager OSS/Pro versions 2.14.5 and below and 3.7.1 and below suffer from multiple cross site scripting vulnerabilities.

macOS AppleEmbeddedOSSupportHostClient::registerNotificationPort Use-After-Free

Posted by deepcore under exploit (No Respond)

The macOS kernel suffers from a use-after-free issue due to a lack of locking in AppleEmbeddedOSSupportHostClient::registerNotificationPort.

HPE iLO4 Add New Administrator User

Posted by deepcore under exploit (No Respond)

HPE iLO4 versions prior to 2.54 add new administrator user exploit.

[dos] macOS Kernel – Use-After-Free Due to Lack of Locking in 'AppleEmbeddedOSSupportHostClient::registerNotificationPort'

Posted by deepcore under Security (No Respond)

macOS Kernel – Use-After-Free Due to Lack of Locking in ‘AppleEmbeddedOSSupportHostClient::registerNotificationPort’

Tags: ,

Geovision Inc. IP Camera / Video Server Remote Command Execution

Posted by deepcore under exploit (No Respond)

Geovision Inc. IP Camera and Video Server remote command execution proof of concept exploit.

Adobe Coldfusion 11.0.03.292866 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Adobe Coldfusion version 11.0.03.292866 BlazeDS java object deserialization remote code execution exploit.

PHP Scripts Mall Doctor Search Script 1.0.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PHP Scripts Mall Doctor Search Script version 1.0.2 suffers from a cross site scripting vulnerability.

Naukri Clone Script 3.0.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Naukri Clone Script version 3.0.3 suffers from a persistent cross site scripting vulnerability.

Entrepreneur Dating Script 2.0.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Entrepreneur Dating Script version 2.0.2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Multilanguage Real Estate MLM Script 3.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Multilanguage Real Estate MLM Script versions 3.0 and below suffer from a persistent cross site scripting vulnerability.