Archive for March, 2018
Posted by deepcore under Security (No Respond)
[remote] Firefox 46.0.1 – ASM.JS JIT-Spray Remote Code Execution
Posted by deepcore under Security (No Respond)
[webapps] Contec Smart Home 4.15 – Unauthorized Password Reset
Posted by deepcore under Security (No Respond)
[papers] Analyze & Attack SSH Protocol
Posted by deepcore under Security (No Respond)
[remote] Firefox 44.0.2 – ASM.JS JIT-Spray Remote Code Execution
Posted by deepcore under Security (No Respond)
http://www.sknhospital.go.th/rest.html
Posted by deepcore under defacement (No Respond)
http://www.sknhospital.go.th/rest.html notified by The WTJ
Tags: defacementTextpattern 4.6.2 SQL Injection
Posted by deepcore under exploit (No Respond)
Textpattern versions 4.6.2 and below suffer from a remote SQL injection vulnerability.
ManageEngine Applications Manage 13.5 Remote Code Execution
Posted by deepcore under exploit (No Respond)
This Metasploit module exploits command injection vulnerability in the ManageEngine Application Manager product. An unauthenticated user can execute a operating system command under the context of privileged user. Publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing given system. This endpoint calls a several internal classes and then executes powershell […]
http://huaysaisankamphaeng.go.th
Posted by deepcore under defacement (No Respond)
http://huaysaisankamphaeng.go.th notified by nighto mearo
Tags: defacement[remote] MikroTik RouterOS < 6.41.3/6.42rc27 – SMB Buffer Overflow
Posted by deepcore under Security (No Respond)