Subscribe via feed.
Archive for April, 2018

http://www.reo8.go.th

Posted by deepcore under defacement (No Respond)

http://www.reo8.go.th notified by The WTJ

Tags:

Cobub Razor 0.8.0 Path Disclosure

Posted by deepcore under exploit (No Respond)

Cobub Razor version 0.8.0 suffers from a path disclosure vulnerability.

Microsoft Internet Explorer 11.371.16299.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer version 11.371.16299.0 suffers from a denial of service vulnerability.

DrayTek VigorACS 2 Unsafe Flex AMF Java Object Deserialization

Posted by deepcore under exploit (No Respond)

DrayTek Vigor ACS server, a remote enterprise management system for DrayTek routers, uses a vulnerable version of the Adobe / Apache Flex Java library that has a deserialisation vulnerability. This can be exploited by an unauthenticated attacker to achieve remote code execution as root / SYSTEM on all versions until 2.2.2. Exploit code included.

Chrome V8 JIT NodeProperties::InferReceiverMaps Type Confusion

Posted by deepcore under exploit (No Respond)

Chrome V8 JIT suffers from a NodeProperties::InferReceiverMaps type confusion vulnerability.

Drupal Avatar Uploader 7.x-1.0-beta8 Arbitary File Download

Posted by deepcore under exploit (No Respond)

Drupal Avatar Uploader module version 7.x-1.0-beta8 suffers from an arbitrary file download vulnerability.

ASUS infosvr Authentication Bypass Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authentication bypass vulnerability in the infosvr service running on UDP port 9999 on various ASUS routers to execute arbitrary commands as root. This Metasploit module launches the BusyBox Telnet daemon on the port specified in the TelnetPort option to gain an interactive remote shell. This Metasploit module was tested successfully […]

lastore-daemon D-Bus Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module attempts to gain root privileges on Deepin Linux systems by using lastore-daemon to install a package. The lastore-daemon D-Bus configuration on Deepin Linux 15.5 permits any user in the sudo group to install arbitrary system packages without providing a password, resulting in code execution as root. By default, the first user created […]

Adobe Flash Slab Rendering Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a slab rendering overflow.

Adobe Flash Sound Playing Overflow

Posted by deepcore under exploit (No Respond)

Adobe Flash suffers from a sound playing overflow.