Subscribe via feed.
Archive for February, 2019

[dos] VSCO 1.1.1.0 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

VSCO 1.1.1.0 – Denial of Service (PoC)

Tags: ,

[dos] Navicat for Oracle 12.1.15 – "Password" Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

Navicat for Oracle 12.1.15 – “Password” Denial of Service (PoC)

Tags: ,

[webapps] MyBB Trash Bin Plugin 1.1.3 – Cross-Site Scripting / Cross-Site Request Forgery

Posted by deepcore under Security (No Respond)

MyBB Trash Bin Plugin 1.1.3 – Cross-Site Scripting / Cross-Site Request Forgery

Tags: ,

runc Host Command Execution

Posted by deepcore under exploit (No Respond)

runc versions prior to 1.0-rc6 (Docker < 18.09.2 host command execution proof of concept exploit.

snapd 2.37 (Ubuntu) dirty_sock Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This exploit bypasses access control checks to use a restricted API function (POST /v2/create-user) of the local snapd service. This queries the Ubuntu SSO for a username and public SSH key of a provided email address, and then creates a local user based on these value. Successful exploitation for this version requires an outbound Internet […]

snapd 2.37 (Ubuntu) dirty_sock Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This exploit bypasses access control checks to use a restricted API function (POST /v2/snaps) of the local snapd service. This allows the installation of arbitrary snaps. Snaps in “devmode” bypass the sandbox and may include an “install hook” that is run in the context of root at install time. dirty_sockv2 leverages the vulnerability to install […]

SYSTORME ISG Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

SYSTORME ISG products ISG-600C, ISG-600H, and ISG-800W suffer from a cross site request forgery vulnerability.

SYSTORME ISG Command Injection

Posted by deepcore under exploit (No Respond)

SYSTORME ISG products ISG-600C, ISG-600H, and ISG-800W suffer from an authenticated command injection vulnerability.

Raisecom Technology GPON-ONU HT803G-07 Command Injection

Posted by deepcore under exploit (No Respond)

Raisecom Technology GPON-ONU HT803G-07 suffers from an authenticated command injection vulnerability in the fmgpon_loid parameter.

Raisecom Technology GPON-ONU HT803G-07 Command Injection

Posted by deepcore under exploit (No Respond)

Raisecom Technology GPON-ONU HT803G-07 suffers from an authenticated command injection vulnerability in the newpass and confpass parameters in /bin/WebMGR.