Subscribe via feed.
Archive for February, 2019

http://www.reh.go.th/owned.htm

Posted by deepcore under defacement (No Respond)

http://www.reh.go.th/owned.htm notified by UnM@SK

Tags:

Apple Security Advisory 2019-2-07-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-2-07-1 – iOS 12.1.4 is now available and addresses memory corruption vulnerabilities.

Tags: , ,

Apple Security Advisory 2019-2-07-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-2-07-2 – macOS Mojave 10.14.3 Supplemental Update is now available and addresses memory corruption and logic issues.

Tags: , ,

Apple Security Advisory 2019-2-07-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-2-07-1 – iOS 12.1.4 is now available and addresses memory corruption and logic issues.

Tags: , ,

Apple Security Advisory 2019-2-07-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-2-07-3 – Shortcuts 2.1.3 for iOS is now available and addresses information disclosure and sandbox escape vulnerabilities.

Tags: , ,

Paypal Inc – Broken Authorization & CSRF Vulnerability

Posted by deepcore under exploit (No Respond)

http://asset.fisheries.go.th/APP/pok.html

Posted by deepcore under defacement (No Respond)

http://asset.fisheries.go.th/APP/pok.html notified by MR.5T1Y0

Tags:

Evince CBT File Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in Evince before version 3.24.1 when opening comic book `.cbt` files. Some file manager software, such as Nautilus and Atril, may allow automatic exploitation without user interaction due to thumbnailer preview functionality. Note that limited space is available for the payload.

NUUO NVRmini upgrade_handle.php Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in the web application of NUUO NVRmini IP camera, which can be done by triggering the writeuploaddir command in the upgrade_handle.php file.

osCommerce 2.3.4.1 SQL Injection

Posted by deepcore under exploit (No Respond)

osCommerce version 2.3.4.1 suffers from multiple remote SQL injection vulnerabilities.