Subscribe via feed.
Archive for September, 2018

DVD Photo Slideshow Professional 8.07 Buffer Overflow

Posted by deepcore under exploit (No Respond)

DVD Photo Slideshow Professional version 8.07 suffers from a buffer overflow vulnerability.

iSmartViewPro 1.5 Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

iSmartViewPro version 1.5 suffers from a buffer overflow vulnerability.

Softneta MedDream PACS Server Premium 6.7.1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

MedDream PACS Server Premium version 6.7.1.1 suffers from a remote SQL injection vulnerability.

Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal

Posted by deepcore under exploit (No Respond)

Softneta MedDream PACS Server Premium version 6.7.1.1 suffers from a directory traversal vulnerability.

Tenable WAS-Scanner 7.4.1708 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Tenable WAS-Scanner version 7.4.1708 suffers from a remote command execution vulnerability.

QNAP Photo Station 5.7.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

QNAP Photo Station version 5.7.0 suffers from a cross site scripting vulnerability.

Apache Struts 2 Namespace Redirect OGNL Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a remote code execution vulnerability in Apache Struts versions 2.3 through 2.3.4, and 2.5 through 2.5.16. Remote code execution can be performed via an endpoint that makes use of a redirect action. Native payloads will be converted to executables and dropped in the server’s temp dir. If this fails, try a […]

NetworkManager Daemon Command Execution

Posted by deepcore under exploit (No Respond)

This is a small tutorial write up that provides a DynoRoot exploit proof of concept.

Apache Roller 5.0.3 XML Injection / File Disclosure

Posted by deepcore under exploit (No Respond)

Apache Roller version 5.0.3 suffers from an XML external entity injection vulnerability that allows for file disclosure.

Jorani Leave Management System 0.6.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Jorani Leave Management System version 0.6.5 suffers from a cross site scripting vulnerability.