Subscribe via feed.
Archive for October, 2018

MensaMax 4.3 Hardcoded Encryption Key Disclosure

Posted by deepcore under exploit (No Respond)

MensaMax version 4.3 performs unencrypted transmission and usage of a hardcoded encryption key.

Ivanti Workspace Control Application PowerGrid RWS Whitelist Bypass

Posted by deepcore under exploit (No Respond)

It was found that the PowerGrid application will execute rundll32.exe from a relative path when it is started with the /RWS command line option. An attacker can abuse this issue to bypass Application Whitelisting in order to run arbitrary code on the target machine. This issue was successfully verified on Ivanti Workspace Control version 10.2.700.1.

Ivanti Workspace Control Application PowerGrid SEE Whitelist Bypass

Posted by deepcore under exploit (No Respond)

It was found that the PowerGrid application can be used to run arbitrary commands via the /SEE command line option. An attacker can abuse this issue to bypass Application Whitelisting in order to run arbitrary code on the target machine. This issue was successfully verified on Ivanti Workspace Control version 10.2.950.0.

Debian/Ubuntu AppArmor evince Policy Bypass

Posted by deepcore under exploit (No Respond)

The Debian/Ubuntu AppArmor policy for evince in bypassable.

H2 Database 1.4.196 Remote Code Execution

Posted by deepcore under exploit (No Respond)

H2 Database version 1.4.196 suffers from a remote code execution vulnerability.

Hotel Booking Engine 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Hotel Booking Engine version 1.0 suffers from a remote SQL injection vulnerability.

Education Website 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Education Website version 1.0 suffers from a remote SQL injection vulnerability.

Singleleg MLM Software 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Singleleg MLM Software version 1.0 suffers from a remote SQL injection vulnerability.

Binary MLM Software 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Binary MLM Software version 1.0 suffers from a remote SQL injection vulnerability.

Flippa Marketplace Clone 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Flippa Marketplace Clone version 1.0 suffers from a remote SQL injection vulnerability.