Subscribe via feed.
Archive for December, 2018

Apache Superset 0.23 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Apache Superset version 0.23 suffers from a remote code execution vulnerability.

PHP Server Monitor 3.3.1 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

PHP Server Monitor version 3.3.1 suffers from a cross site request forgery vulnerability.

Joomla! JE Photo Gallery 1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla! JE Photo Gallery component version 1.1 suffers from a remote SQL injection vulnerability.

FreshRSS 1.11.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

FreshRSS version 1.11.1 suffers from multiple cross site scripting vulnerabilities.

CubeCart 6.2.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CubeCart version 6.2.2 suffers from a cross site scripting vulnerability.

NEC Univerge Sv9100 WebPro 6.00.00 Predictable Session ID / Cleartext Passwords

Posted by deepcore under exploit (No Respond)

NEC Univerge Sv9100 WebPro version 6.00.00 suffers from predictable session identifiers and cleartext password vulnerabilities.

Emacs movemail Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a SUID installation of the Emacs movemail utility to run a command as root by writing to 4.3BSD’s /usr/lib/crontab.local. The vulnerability is documented in Cliff Stoll’s book The Cuckoo’s Egg.

HP Intelligent Management Java Deserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett Packard Enterprise Intelligent Management Center. Authentication is not required to exploit this vulnerability. The specific flaw exists within the WebDMDebugServlet, which listens on TCP ports 8080 and 8443 by default. The issue results from the lack of proper validation of user-supplied […]

[webapps] HasanMWB 1.0 – SQL Injection

Posted by deepcore under Security (No Respond)

HasanMWB 1.0 – SQL Injection

Tags: ,

[shellcode] Linux/x86 – /usr/bin/head -n99 cat etc/passwd Shellcode (61 Bytes)

Posted by deepcore under Security (No Respond)

Linux/x86 – /usr/bin/head -n99 cat etc/passwd Shellcode (61 Bytes)

Tags: ,