Subscribe via feed.
Archive for March, 2018

DEWESoft X3 Remote Internal Command Access

Posted by deepcore under exploit (No Respond)

DEWESoft X3 suffers from a remote internal command access vulnerability.

Chromium Android Writable SharedMemory Descriptors

Posted by deepcore under exploit (No Respond)

Chromium suffers from an issues where read-only SharedMemory descriptors on Android are writable.

SC 7.16 Buffer Overflow

Posted by deepcore under exploit (No Respond)

SC version 7.16 suffers from a stack-based buffer overflow vulnerability.

Chromium mojo::WrapSharedMemoryHandle Insufficient Call

Posted by deepcore under exploit (No Respond)

Chromium suffers from an issue where calling mojo::WrapSharedMemoryHandle is insufficient to produce read-only descriptors for IPC.

Chromium memory_instrumentation::mojom::Coordinator Information Disclosure

Posted by deepcore under exploit (No Respond)

Chromium suffers from an information disclosure vulnerability via the memory_instrumentation::mojom::Coordinator interface in the resource_coordinator service.

Prisma Industriale Checkweigher PrismaWEB 1.21 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Prisma Industriale Checkweigher PrismaWEB version 1.21 suffers from a disclosure of hard-coded credentials allowing an attacker to effectively bypass authentication.

SecurEnvoy SecurMail 9.1.501 XSS / CSRF / Traversal

Posted by deepcore under exploit (No Respond)

SecurEnvoy SecurMail version 9.1.501 suffers from cross site request forgery, cross site scripting, insecure direct object reference, missing authentication and authorization, and path traversal vulnerabilities.

Shopware 5.3.7 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Shopware versions 4.0.1 through 5.3.7 suffer from a cross site request forgery vulnerability. Malicious, third-party websites may abuse this API to list, add or remove products from a user’s cart.

http://hhdc.anamai.moph.go.th/n.php

Posted by deepcore under defacement (No Respond)

http://hhdc.anamai.moph.go.th/n.php notified by xCypressx

Tags:

[webapps] Tuleap 9.17.99.189 – Blind SQL Injection

Posted by deepcore under Security (No Respond)

Tuleap 9.17.99.189 – Blind SQL Injection

Tags: ,