Subscribe via feed.
Archive for July, 2018

WeChat Pay SDK XXE Injection

Posted by deepcore under exploit (No Respond)

The WePay Chat SDK suffers from an XML external entity injection vulnerability.

ntop-ng Authentication Bypass

Posted by deepcore under exploit (No Respond)

ntop-ng versions prior to 3.4.180617 suffer from a deterministic session ID vulnerability.

NuCom NC-WR644GACV Unauthenticated Configuration File Download

Posted by deepcore under exploit (No Respond)

NuCom NC-WR644GACV with software versions STA 005 and below suffer from a configuration file download vulnerability that allows for extraction of the administrative credentials.

openslp 2.0.0 Double Free

Posted by deepcore under exploit (No Respond)

An issue was found in openslp version 2.0.0 that can be used to induce a double free bug or memory corruption by corrupting glibc’s doubly-linked memory chunk list. An exploit in included in the advisory.

OX App Suite 7.8.4 XSS / XML Injection / Information Disclosure

Posted by deepcore under exploit (No Respond)

OX App Suite version 7.8.5 suffers from XML external entity injection, information disclosure, and cross site scripting vulnerabilities.

Boxoft WAV To MP3 Converter 1.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a stack buffer overflow in Boxoft WAV to MP3 Converter versions 1.0 and 1.1. By constructing a specially crafted WAV file and attempting to convert it to an MP3 file in the application, a buffer is overwritten, which allows for running shellcode.

[webapps] ModSecurity 3.0.0 – Cross-Site Scripting

Posted by deepcore under Security (No Respond)

ModSecurity 3.0.0 – Cross-Site Scripting

Tags: ,

[remote] Nagios XI 5.2.6-5.4.12 – Chained Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Nagios XI 5.2.6-5.4.12 – Chained Remote Code Execution (Metasploit)

Tags: ,

[remote] FTPShell client 6.70 (Enterprise edition) – Stack Buffer Overflow (Metasploit)

Posted by deepcore under Security (No Respond)

FTPShell client 6.70 (Enterprise edition) – Stack Buffer Overflow (Metasploit)

Tags: ,

[webapps] VMware NSX SD-WAN Edge < 3.1.0 – Command Injection

Posted by deepcore under Security (No Respond)

VMware NSX SD-WAN Edge < 3.1.0 – Command Injection

Tags: ,