Subscribe via feed.
Archive for February, 2018

Whole Vibratissimo Smart Sex Toy XSS / Disclosure / Authentication

Posted by deepcore under exploit (No Respond)

Multiple versions of Whole Vibratissimo Smart Sex Toy suffer from credential disclosure, exposed administrative interface, cleartext storage of passwords, unauthenticated bluetooth LE connection, and other vulnerabilities. These devices screw you in more way than one.

Geovision Inc. IP Camera Remote Command Execution / Stack Overflow

Posted by deepcore under exploit (No Respond)

Geovision Inc. devices GV-BX1500 version 3.10 2016-12-02 and GV-MFD1501 version 3.12 2017-06-19 suffer from remote command execution, stack overflow, double free, and other vulnerabilities.

Advance Loan Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Advance Loan Management System version 1.0 suffers from a remote SQL injection vulnerability.

Joomla! JEXTN Classified 1.0.0 SQL Injection

Posted by deepcore under exploit (No Respond)

JEXTN Classified component version 1.0.0 suffers from a remote SQL injection vulnerability.

Microsoft Windows Subsystem For Linux Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows Subsystem for Linux execve() local privilege escalation exploit.

Joomla! Jimtawl 2.2.5 Shell Upload

Posted by deepcore under exploit (No Respond)

Joomla! Jimtawl component version 2.2.5 suffers from a remote shell upload vulnerability.

Flexense SyncBreeze Enterprise 10.3.14 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Flexense SyncBreeze Enterprise versions 10.3.14 and below suffer from a buffer overflow vulnerability.

Real Estate Custom Script 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Real Estate Custom Script version 1.0 suffers from a remote SQL injection vulnerability.

Fancy Clone Script SQL Injection

Posted by deepcore under exploit (No Respond)

Fancy Clone Script suffers from a search_browse_product remote SQL injection vulnerability.

Joomla! JE PayperVideo 3.0.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla! JE PayperVideo component version 3.0.0 suffers from a remote SQL injection vulnerability.