Subscribe via feed.
Archive for November, 2018

[webapps] Facturation System 1.0 – 'modid' SQL Injection

Posted by deepcore under Security (No Respond)

Facturation System 1.0 – ‘modid’ SQL Injection

Tags: ,

[dos] HeidiSQL 9.5.0.5196 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

HeidiSQL 9.5.0.5196 – Denial of Service (PoC)

Tags: ,

[webapps] Data Center Audit 2.6.2 – 'username' SQL Injection

Posted by deepcore under Security (No Respond)

Data Center Audit 2.6.2 – ‘username’ SQL Injection

Tags: ,

[webapps] TufinOS 2.17 Build 1193 – XML External Entity Injection

Posted by deepcore under Security (No Respond)

TufinOS 2.17 Build 1193 – XML External Entity Injection

Tags: ,

Everus.org 1.0.7 Second Factor Modification

Posted by deepcore under exploit (No Respond)

The Everus.org Android application version 1.0.7 has a fundamental design flaw where the client can send a random phone number during the second factor flow and the server will update the number on file.

Everus.org 1.0.7 Second Factor Client-Side Validation

Posted by deepcore under exploit (No Respond)

The Everus.org Android application version1.0.7 has a fundamental design flaw where the server provides the second factor to the client for comparison instead of properly validating it server-side.

Microsoft Windows 10 Build 17134 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows 10 Build 17134 local privilege escalation exploit with UAC bypass.

OpenSLP 2.0.0 Out-Of-Bounds

Posted by deepcore under exploit (No Respond)

OpenSLP version 2.0.0 suffers from multiple out-of-bounds vulnerabilities.

Cisco Immunet / Cisco AMP For Endpoints Scanning Denial Of Service

Posted by deepcore under exploit (No Respond)

A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being analyzed for threats. The vulnerability is due […]

D-LINK Central WifiManager (CWM 100) 1.03 r0098 Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

The FTP Server component of the D-LINK Central WifiManager can be used as a man-in-the-middle machine allowing PORT Command bounce scan attacks. This vulnerability allows remote attackers to abuse your network and discreetly conduct network port scanning. Victims will then think these scans are originating from the D-LINK network running the afflicted FTP Server and […]