Subscribe via feed.
Archive for November, 2018

Linux Nested User Namespace idmap Limit Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18, and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user namespaces and kernel uid/gid mappings allow elevation to root (CVE-2018-18955). The target system must have unprivileged user namespaces enabled and the newuidmap and newgidmap helpers installed (from uidmap package). This Metasploit module […]

PHP imap_open Remote Code Execution

Posted by deepcore under exploit (No Respond)

The imap_open function within PHP, if called without the /norsh flag, will attempt to preauthenticate an IMAP session. On Debian based systems, including Ubuntu, rsh is mapped to the ssh binary. Ssh’s ProxyCommand option can be passed from imap_open to execute arbitrary commands. While many custom applications may use imap_open, this exploit works against the […]

BMC Remedy 7.1 User Impersonation

Posted by deepcore under exploit (No Respond)

An impersonation issue in BMC Remedy version 7.1 may lead to incorrect user context in Remedy AR System Server.

Avahi 0.7 Denial Of Service

Posted by deepcore under exploit (No Respond)

Avahi-daemon in Avahi version through 0.7 inadvertently sends Legacy Unicast Responses to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.

Cisco WebEx Meetings Privilege Escalation

Posted by deepcore under exploit (No Respond)

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow a local attacker to elevate privileges. This vulnerability is related to a previous security issue fixed by Cisco in October. Affected versions include Cisco Webex Meetings Desktop App releases prior to 33.6.4 and Cisco Webex Productivity Tools releases 32.6.0 […]

WordPress SEO (Yoast SEO) 9.1 Race Condition / Command Execution

Posted by deepcore under exploit (No Respond)

WordPress SEO (Yoast SEO) plugin versions 9.1 and below suffer from a race condition that allows for command execution.

Unitrends Enterprise Backup bpserverd Privilege Escalation

Posted by deepcore under exploit (No Respond)

It was discovered that the Unitrends bpserverd proprietary protocol, as exposed via xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target system. This is very similar to exploits/linux/misc/ueb9_bpserverd however it runs against the localhost by dropping […]

Joomla Fabrik 3.9 CSRF / LFI / Shell Upload

Posted by deepcore under exploit (No Respond)

Joomla Fabrik component version 3.9 suffers from cross site request forgery, local file inclusion, and remote shell upload vulnerabilities.

Joomla DJ Image Slider 3.2.3 Database Disclosure

Posted by deepcore under exploit (No Respond)

Joomla DJ Image Slider component version 3.2.3 suffers from a database disclosure vulnerability.

Joomla Event Booking 3.8.3 Database Disclosure

Posted by deepcore under exploit (No Respond)

Joomla Event Booking component version 3.8.3 suffers from a database backup disclosure vulnerability.