Subscribe via feed.
Archive for June, 2018

http://muangfang.go.th/muangfang/mainfile/8ZViYMF6zcJHhtml

Posted by deepcore under defacement (No Respond)

http://muangfang.go.th/muangfang/mainfile/8ZViYMF6zcJHhtml notified by Evil-Root

Tags:

Microsoft Internet Explorer HTML Help Control 4.74 Bypass

Posted by deepcore under exploit (No Respond)

Microsoft Internet Explorer HTML Help Control version 4.74 local zone bypass exploit. Proof of concept code for an ancient vulnerability.

PoDoFo 0.9.5 Buffer Overflow

Posted by deepcore under exploit (No Respond)

PoDoFo version 0.9.5 suffers from a buffer overflow vulnerability.

Liferay Portal Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

Liferay Portal versions prior to 7.0.4 suffer from a server-side request forgery vulnerability.

Polaris Office 2017 8.1 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Polaris Office 2017 version 8.1 allows attackers to execute arbitrary code via a trojan horse “puiframeworkproresenu.dll” file in the current working directory, due to a search order flaw vulnerability.

HP Enterprise VAN SDN Controller 2.7.18.0503 Remote Root

Posted by deepcore under exploit (No Respond)

HP Enterprise VAN SDN Controller version 2.7.18.0503 suffers from an unauthenticated remote root vulnerability. A hard-coded service token can be used to bypass authentication. Built-in functionality can be exploited to deploy and execute a malicious deb file containing a backdoor. A weak sudoers configuration can then be abused to escalate privileges to root. A second […]

Quest KACE Systems Management Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in Quest KACE Systems Management Appliance version 8.0.318 (and possibly prior). The download_agent_installer.php file allows unauthenticated users to execute arbitrary commands as the web server user www. A valid Organization ID is required. The default value is 1. A valid Windows agent version number must also be […]

ASUS WRT-AC66U 3.x – Cross Site Scripting Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered mutliple cross site scripting vulnerabilities in the offici…

GhostMail – (Status Message) Persistent Web Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered an application-side vulnerability in the official GhostMail c…

[webapps] WordPress < 4.9.6 – (Authenticated) Arbitrary File Deletion

Posted by deepcore under Security (No Respond)

WordPress < 4.9.6 – (Authenticated) Arbitrary File Deletion

Tags: ,