Subscribe via feed.
Archive for January, 2019

iOS / macOS task_swap_mach_voucher() Use-After-Free

Posted by deepcore under exploit (No Respond)

task_swap_mach_voucher() on iOS and macOS have an issue where task_swap_mach_voucher() does not respect MIG semantics leading to a use-after-free condition.

iOS / macOS task_swap_mach_voucher() Use-After-Free

Posted by deepcore under exploit (No Respond)

task_swap_mach_voucher() on iOS and macOS have an issue where task_swap_mach_voucher() does not respect MIG semantics leading to a use-after-free condition.

ImpressCMS 1.3.11 SQL Injection

Posted by deepcore under exploit (No Respond)

ImpressCMS version 1.3.11 suffers from a remote SQL injection vulnerability.

ImpressCMS 1.3.11 SQL Injection

Posted by deepcore under exploit (No Respond)

ImpressCMS version 1.3.11 suffers from a remote SQL injection vulnerability.

Cisco RV320 Unauthenticated Configuration Export

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the configuration of a Cisco RV320 router may be exported without authentication through the device’s web interface. Affected versions include 1.4.2.15 and 1.4.2.17.

Cisco RV320 Unauthenticated Configuration Export

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the configuration of a Cisco RV320 router may be exported without authentication through the device’s web interface. Affected versions include 1.4.2.15 and 1.4.2.17.

Cisco RV320 Unauthenticated Diagnostic Data Retrieval

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the Cisco RV320 router exposes sensitive diagnostic data without authentication through the device’s web interface. Versions affected include 1.4.2.15 and 1.4.2.17.

Cisco RV320 Unauthenticated Diagnostic Data Retrieval

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the Cisco RV320 router exposes sensitive diagnostic data without authentication through the device’s web interface. Versions affected include 1.4.2.15 and 1.4.2.17.

Cisco RV320 Command Injection

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a command injection vulnerability in the web-based certificate generator feature of the Cisco RV320 router. Versions 1.4.2.15 through 1.4.2.19 are affected. Fixed in version 1.4.2.20.

Cisco RV320 Command Injection

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a command injection vulnerability in the web-based certificate generator feature of the Cisco RV320 router. Versions 1.4.2.15 through 1.4.2.19 are affected. Fixed in version 1.4.2.20.