Subscribe via feed.
Archive for June, 2018

CSV Import And Export 1.1.0 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

CSV Import and Export version 1.1.0 suffers from cross site scripting and remote SQL injection vulnerabilities.

PHP Dashboards NEW 5.5 SQL Injection

Posted by deepcore under exploit (No Respond)

PHP Dashboards NEW version 5.5 suffers from a remote SQL injection vulnerability.

New STAR 2.1 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

New STAR version 2.1 suffers from cross site scripting and remote SQL injection vulnerabilities.

TAC Xenta 511 / 911 Credential Disclosure

Posted by deepcore under exploit (No Respond)

TAC Xenta 511 and 911 suffer from a credential disclosure vulnerability.

PageKit CMS 1.0.13 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PageKit CMS version 1.0.13 suffers from a cross site scripting vulnerability.

Quest DR Series Disk Backup Software 4.0.3 Code Execution

Posted by deepcore under exploit (No Respond)

Quest DR Series Disk Backup Software version 4.0.3 suffers from multiple code execution vulnerabilities.

Windows UAC Protection Bypass (Via Slui File Handler Hijack)

Posted by deepcore under exploit (No Respond)

This Metasploit module will bypass UAC on Windows 8-10 by hijacking a special key in the Registry under the Current User hive, and inserting a custom command that will get invoked when any binary (.exe) application is launched. But slui.exe is an auto-elevated binary that is vulnerable to file handler hijacking. When we run slui.exe […]

Quest KACE System Management Appliance 8.0 (Build 8.0.318) XSS / Traversal / Code Execution / SQL Injection

Posted by deepcore under exploit (No Respond)

Quest KACE System Management Appliance version 8.0 (Build 8.0.318) suffers from code execution, cross site scripting, path traversal, remote SQL injection, and various other vulnerabilities.

[dos] Epiphany 3.28.2.1 – Denial of Service

Posted by deepcore under Security (No Respond)

Epiphany 3.28.2.1 – Denial of Service

Tags: ,

[remote] Git < 2.17.1 – Remote Code Execution

Posted by deepcore under Security (No Respond)

Git < 2.17.1 – Remote Code Execution

Tags: ,