Subscribe via feed.
Archive for July, 2018

Zoho ManageEngine 13 (13790 build) XSS / File Read / File Deletion

Posted by deepcore under exploit (No Respond)

Zoho ManageEngine version 13 (13790 build) suffers from file read, file deletion, and cross site scripting vulnerabilities.

[remote] Microsoft Windows – 'dnslint.exe' Drive-By Download

Posted by deepcore under Security (No Respond)

Microsoft Windows – ‘dnslint.exe’ Drive-By Download

Tags: ,

[webapps] Davolink DVW 3200 Router – Password Disclosure

Posted by deepcore under Security (No Respond)

Davolink DVW 3200 Router – Password Disclosure

Tags: ,

[papers] File Upload Restrictions Bypass

Posted by deepcore under Security (No Respond)

File Upload Restrictions Bypass

Tags: ,

[webapps] NUUO NVRmini – 'upgrade_handle.php' Remote Command Execution

Posted by deepcore under Security (No Respond)

NUUO NVRmini – ‘upgrade_handle.php’ Remote Command Execution

Tags: ,

[local] Splinterware System Scheduler Pro 5.12 – Buffer Overflow (SEH)

Posted by deepcore under Security (No Respond)

Splinterware System Scheduler Pro 5.12 – Buffer Overflow (SEH)

Tags: ,

Oracle Fusion Middleware 12c (12.2.1.3.0) WebLogic SAML Issues

Posted by deepcore under exploit (No Respond)

Two vulnerabilities were discovered within the Oracle WebLogic SAML service provider authentication mechanism. By inserting an XML comment into the SAML NameID tag, an attacker can coerce the SAML service provider to log in as another user. Additionally, WebLogic does not require signed SAML assertions in the default configuration. By omitting the signature portions from […]

Microsoft dnslint.exe DNS Tool Forced Drive-By Download

Posted by deepcore under exploit (No Respond)

Microsoft’s dnslint.exe tool does not verify domain names when parsing DNS text-files using the “/ql” switch making it prone to forced drive-by downloads, providing an end user is tricked into using a server text-file containing a script/binary reference instead of a normally expected domain name.

LibRaw 0.18.11 Denial Of Service

Posted by deepcore under Apple (No Respond)

Secunia Research has discovered multiple vulnerabilities in LibRaw, which can be exploited by malicious people to cause a DoS (Denial of Service). An integer overflow error within the “parse_qt()” function (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file. An integer overflow error within the “identify()” function (internal/dcraw_common.cpp) […]

Tags: , ,

[webapps] GeoVision GV-SNVR0811 – Directory Traversal

Posted by deepcore under Security (No Respond)

GeoVision GV-SNVR0811 – Directory Traversal

Tags: ,