Subscribe via feed.
Archive for February, 2019

[remote] Adobe Flash Player – DeleteRangeTimelineOperation Type Confusion (Metasploit)

Posted by deepcore under Security (No Respond)

Adobe Flash Player – DeleteRangeTimelineOperation Type Confusion (Metasploit)

Tags: ,

[webapps] Coship Wireless Router 4.0.0.x/5.0.0.x – WiFi Password Reset

Posted by deepcore under Security (No Respond)

Coship Wireless Router 4.0.0.x/5.0.0.x – WiFi Password Reset

Tags: ,

[dos] AirDroid 4.2.1.6 – Denial of Service

Posted by deepcore under Security (No Respond)

AirDroid 4.2.1.6 – Denial of Service

Tags: ,

OpenText Documentum Webtop 5.3 SP2 Open Redirect

Posted by deepcore under exploit (No Respond)

OpenText Documentum Webtop version 5.3.SP2 suffers from an open redirection vulnerability.

Amazon FireOS 5.3.6.3 Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

Amazon FireOS version 5.3.6.3 suffers from a content injection vulnerability via man-in-the-middle attacks.

Ericsson Active Library Explorer (ALEX) 14.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Ericsson Active Library Explorer (ALEX) version 14.3 suffers from a cross site scripting vulnerability.

SAMSUNG X7400GX Sync Thru Web Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 suffers from multiple cross site scripting vulnerabilities.

Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 XSS

Posted by deepcore under exploit (No Respond)

Zoho ManageEngine Netflow Analyzer Professional version 7.0.0.2 suffers from multiple cross site scripting vulnerabilities.

IPFire 2.21 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

IPFire version 2.21 suffers from multiple cross site scripting vulnerabilities.

Adobe Flash Player DeleteRangeTimelineOperation Type Confusion

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a type confusion on Adobe Flash Player, which was originally found being successfully exploited in the wild. This module has been tested successfully on: macOS Sierra 10.12.3, Safari and Adobe Flash Player 21.0.0.182, Firefox and Adobe Flash Player 21.0.0.182.