Subscribe via feed.
Archive for January, 2019

Joomla! J-BusinessDirectory 4.9.7 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla! J-BusinessDirectory component version 4.9.7 suffers from a remote SQL injection vulnerability.

Joomla! Easy Shop 1.2.3 Local File Inclusion

Posted by deepcore under exploit (No Respond)

Joomla! Easy Shop component version 1.2.3 suffers from a local file inclusion vulnerability.

Microsoft Windows Contact File HTML Link Injection Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Windows has a flaw where a contact file can be leveraged with a malicious mailto: link to achieve code execution.

DNN 9.1 XML Related Cross Site Scripting

Posted by deepcore under exploit (No Respond)

DNN version 9.1 suffers from a cross site scripting issue that can be achieved via an XML vulnerability.

Abantecart 1.2.12 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Abantecart version 1.2.12 suffers from a cross site scripting vulnerability.

Coppermine 1.5.46 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Coppermine version 1.5.46 suffers from multiple cross site scripting vulnerabilities.

Ghostscript Pseudo-Operator Remote Code Execution

Posted by deepcore under exploit (No Respond)

Ghostscript has an issue with pseudo-operators that can lead to remote code execution. Version 9.26 is affected.

AddressSanitizer (ASan) SUID Executable Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module attempts to gain root privileges on Linux systems using setuid executables compiled with AddressSanitizer (ASan). ASan configuration related environment variables are permitted when executing setuid executables built with libasan. The log_path option can be set using the ASAN_OPTIONS environment variable, allowing clobbering of arbitrary files, with the privileges of the setuid user. […]

Apple Security Advisory 2019-1-22-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-1-22-1 – iOS 12.1.3 is now available and addresses buffer overflow, code execution, cross site scripting, and denial of service vulnerabilities.

Tags: , ,

Apple Security Advisory 2019-1-22-6

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-1-22-6 – iCloud for Windows 7.10 is now available and addresses code execution and cross site scripting vulnerabilities.

Tags: , ,