Subscribe via feed.
Archive for May, 2018

TP-Link TL-WR840N / TL-WR841N Authentication Bypass

Posted by deepcore under exploit (No Respond)

TP-Link TL-WR840N and TL-WR841N suffer from an authentication bypass vulnerability.

Joomla JoomOCShop 1.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Joomla JoomOCShop component version 1.0 suffers from a cross site request forgery vulnerability.

Joomla Full Social 1.1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla Full Social extension version 1.1.0 suffers from a remote SQL injection vulnerability.

WordPress Events Calendar 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress Events Calendar plugin version 1.0 suffers from a remote SQL injection vulnerability.

libmobi 0.3 Information Disclosure

Posted by deepcore under exploit (No Respond)

The mobi_parse_mobiheader function in read.c in libmobi version 0.3 allows remote attackers to cause an information disclosure (heap-buffer-overflow out-of-bounds read) via a crafted mobi file.

Appnitro MachForm SQL Injection / Traversal / File Upload

Posted by deepcore under exploit (No Respond)

Appnitro MachForm suffers from remote file upload, remote SQL injection, and path traversal vulnerabilities.

Facebook Graph OpenSearch Phone Number Metadata Crosswalk Mapping

Posted by deepcore under exploit (No Respond)

Facebook Graph OpenSearch Phone Number metadata crosswalk mapping proof of concept exploit.

IssueTrak 7.0 SQL Injection

Posted by deepcore under exploit (No Respond)

IssueTrak version 7.0 suffers from a remote SQL injection vulnerability.

Facebook Clone Script 1.0.5 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Facebook Clone Script version 1.0.5 suffers from a cross site request forgery vulnerability.

MyBB ChangUonDyU 1.0.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

MyBB ChangUonDyU plugin version 1.0.2 suffers from a cross site scripting vulnerability.