Subscribe via feed.
Archive for January, 2019

Microsoft Windows .contact Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw is due to the processing of “.contact” files node param which takes an expected website value, […]

doorGets CMS 7.0 File Download

Posted by deepcore under exploit (No Respond)

doorGets CMS version 7.0 suffers from a file download vulnerability.

ShoreTel / Mitel Connect ONSITE ST14.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

ShoreTel / Mitel Connect ONSITE ST14.2 suffers from a remote code execution vulnerability.

Blueimp jQuery File Upload 9.22.0 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Blueimp jQuery File Upload versions 9.22.0 and below suffer from a remote file upload vulnerability.

[local] Microsoft Windows CONTACT – Remote Code Execution

Posted by deepcore under Security (No Respond)

Microsoft Windows CONTACT – Remote Code Execution

Tags: ,

[webapps] Oracle Reports Developer Component 12.2.1.3 – Cross-site Scripting

Posted by deepcore under Security (No Respond)

Oracle Reports Developer Component 12.2.1.3 – Cross-site Scripting

Tags: ,

[local] Microsoft Windows 10 – XmlDocument Insecure Sharing Privilege Escalation

Posted by deepcore under Security (No Respond)

Microsoft Windows 10 – XmlDocument Insecure Sharing Privilege Escalation

Tags: ,

[dos] NTPsec 1.1.2 – 'ctl_getitem' Out-of-Bounds Read (PoC)

Posted by deepcore under Security (No Respond)

NTPsec 1.1.2 – ‘ctl_getitem’ Out-of-Bounds Read (PoC)

Tags: ,

[dos] Spotify 1.0.96.181 – 'Proxy configuration' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

Spotify 1.0.96.181 – ‘Proxy configuration’ Denial of Service (PoC)

Tags: ,

[dos] WebKit JSC JIT – GetIndexedPropertyStorage Use-After-Free

Posted by deepcore under Security (No Respond)

WebKit JSC JIT – GetIndexedPropertyStorage Use-After-Free

Tags: ,