Subscribe via feed.
Archive for October, 2018

FLIR Systems FLIR Brickstream 3D+ Unauthenticated Config Download File Disclosure

Posted by deepcore under exploit (No Respond)

The FLIR Brickstream 3D+ sensor is vulnerable to unauthenticated config download and file disclosure vulnerability when calling the ExportConfig REST API (getConfigExportFile.cgi). This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access.

FLIR Systems FLIR Brickstream 3D+ Unauthenticated RTSP Stream Disclosure

Posted by deepcore under exploit (No Respond)

The FLIR Brickstream 3D+ sensor is vulnerable to unauthenticated and unauthorized live RTSP video stream access.

Solaris RSH Stack Clash Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in RSH on unpatched Solaris systems which allows users to gain root privileges. The stack guard page on unpatched Solaris systems is of insufficient size to prevent collisions between the stack and heap memory, aka Stack Clash. This Metasploit module uploads and executes Qualys’ Solaris_rsh.c exploit, which exploits a […]

Library CMS 2.1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Library CMS version 2.1.1 suffers from a cross site scripting vulnerability.

WordPress Support Board 1.2.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Support Board plugin version 1.2.3 suffers from a persistent cross site scripting vulnerability.

[webapps] Rukovoditel Project Management CRM 2.3 – 'path' SQL Injection

Posted by deepcore under Security (No Respond)

Rukovoditel Project Management CRM 2.3 – ‘path’ SQL Injection

Tags: ,

[webapps] Kados R10 GreenBee – 'release_id' SQL Injection

Posted by deepcore under Security (No Respond)

Kados R10 GreenBee – ‘release_id’ SQL Injection

Tags: ,

[webapps] Kados R10 GreenBee – 'release_id' SQL Injection

Posted by deepcore under Security (No Respond)

Kados R10 GreenBee – ‘release_id’ SQL Injection

Tags: ,

[webapps] HotelDruid 2.2.4 – 'anno' SQL Injection

Posted by deepcore under Security (No Respond)

HotelDruid 2.2.4 – ‘anno’ SQL Injection

Tags: ,

[webapps] HotelDruid 2.2.4 – 'anno' SQL Injection

Posted by deepcore under Security (No Respond)

HotelDruid 2.2.4 – ‘anno’ SQL Injection

Tags: ,