Subscribe via feed.
Archive for March, 2018

Rapid Scada 5.5.0 Insecure Permissions

Posted by deepcore under exploit (No Respond)

Rapid Scada version 5.5.0 suffers from an insecure permission vulnerability.

Bravo Tejari Web Portal Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Bravo Tejari Web Portal suffers from a cross site request forgery vulnerability.

Xion 1.0.125 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Xion version 1.0.125 .m3u file local SEH-based unicode buffer overflow exploit.

Memcached memcrashed Denial Of Service

Posted by deepcore under exploit (No Respond)

This is a proof of concept exploit for the memcached denial of service vulnerability.

Dup Scout Enterprise 10.5.12 Share Username Buffer Overflow

Posted by deepcore under exploit (No Respond)

Dup Scout Enterprise version 10.5.12 suffers from a share username local buffer overflow vulnerability.

Magento User Info Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Magento suffers from user information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

Magento Backups Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Magento Backups suffer from a cross site request forgery vulnerability. Versions affected include Magento Open Source prior to 1.9.3.8, Magento Commerce prior to 1.14.3.8, Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

Magento Downloadable Products Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Magento suffers from downloadable product information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

Magento Product Attributes Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Magento suffers from product attribute information related cross site scripting vulnerabilities. Versions affected include Magento 2.0 prior to 2.0.18, Magento 2.1 prior to 2.1.12, and Magento 2.2 prior to 2.2.3.

[webapps] Redaxo CMS Addon MyEvents 2.2.1 – SQL Injection

Posted by deepcore under Security (No Respond)

Redaxo CMS Addon MyEvents 2.2.1 – SQL Injection

Tags: ,