Subscribe via feed.
Archive for September, 2018

PDF Explorer 1.5.66.2 Denial Of Service

Posted by deepcore under exploit (No Respond)

PDF Explorer version 1.5.66.2 denial of service proof of concept exploit.

iCash 7.6.5 Denial Of Service

Posted by deepcore under exploit (No Respond)

iCash version 7.6.5 denial of service proof of concept exploit.

Rubedo CMS 3.4.0 Directory Traversal

Posted by deepcore under exploit (No Respond)

Rubedo CMS version 3.4.0 suffers from a directory traversal vulnerability.

CirCarLife SCADA 4.3.0 Credential Disclosure

Posted by deepcore under exploit (No Respond)

CirCarLife SCADA version 4.3.0 suffers from a credential disclosure vulnerability.

Bayanno Hospital Management System 4.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Bayanno Hospital Management System version 4.0 suffers from a cross site scripting vulnerability.

Chrome OS gRPC garcon Command Execution

Posted by deepcore under exploit (No Respond)

There is a variety of RPC communication channels between the Chrome OS host system and the crosvm guest. This bug report focuses on communication on TCP port 8889, which is used by the “garcon” service. garcon uses gRPC, which is an RPC protocol that sends protobufs over plaintext HTTP/2. (Other system components communicate with the […]

Tor Browser SMB Deanonymization / Information Disclosure

Posted by deepcore under exploit (No Respond)

Tor Browser versions prior to 8.0 are affected by an information disclosure vulnerability that allows remote attackers to bypass the intended anonymity feature and discover a client IP address. The vulnerability affects Windows users only and needs user interaction to be exploited.

Seagate Personal Cloud Information Disclosure

Posted by deepcore under exploit (No Respond)

Seagate Personal Cloud is a consumer-grade Network-Attached Storage device (NAS). It was found that the web application used to manage the NAS is affected by various unauthenticated information disclosure vulnerabilities. The device is configured to trust any CORS origin, and is accessible via the personalcloud.local domain name. Due to this it is possible for any […]

HiScout GRC Suite File Upload

Posted by deepcore under exploit (No Respond)

HiScout GRC Suite versions prior to 3.1.5 suffer from a file upload vulnerability. An authenticated attacker with the permission to edit or add a “WebSiteElement” to the “content” pages is able to upload any file with any file extension to the data directory of the application. This directory is in the web root and the […]

Wisetail Learning Ecosystem 4.11.6 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Wisetail Learning Ecosystem (LE) versions up to 4.11.6 suffer from multiple insecure direct object reference vulnerabilities that allow an attacker to download files and get access to the non-purchased course quiz test via a modified id parameter.