Subscribe via feed.
Archive for February, 2019

River Past Audio Converter 7.7.16 Buffer Overflow

Posted by deepcore under exploit (No Respond)

River Past Audio Converter version 7.7.16 buffer overflow SEH exploit.

Smoothwall Express 3.1-SP4-polar-x86_64-update9 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Smoothwall Express version 3.1-SP4-polar-x86_64-update9 suffers from a cross site scripting vulnerability.

WordPress WP User Manager 2.0.8 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress WP User Manager plugin version 2.0.8 suffers from a remote shell upload vulnerability.

Cisco ISE 2.4.0 XSS / Remote Code Execution

Posted by deepcore under exploit (No Respond)

Cisco Identity Services Engine (ISE) version 2.4.0 suffers from cross site scripting, java deserialization, and in conjunction can lead to remote code execution. Full exploit provided.

OSCI-Transport Library 1.2 1.8.1 Insecure Crypto / Signature Bypass

Posted by deepcore under exploit (No Respond)

OSCI-Transport Library 1.2 for German e-Government versions 1.8.1 and below suffer from an insecure cryptographic implementation and signature bypass vulnerabilities.

WordPress Forminator 1.5.4 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress Forminator plugin version 1.5.4 suffers from cross site scripting and remote SQL injection vulnerabilities.

WordPress Quiz And Survey Master 6.0.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Quiz and Survey Master plugin version 6.0.4 suffers from a cross site scripting vulnerability.

WordPress Blog2Social 5.0.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Blog2Social plugin version 5.0.2 suffers from a cross site scripting vulnerability.

Device Monitoring Studio 8.10.00.8925 Denial Of Service

Posted by deepcore under exploit (No Respond)

Device Monitoring Studio version 8.10.00.8925 denial of service proof of concept exploit.

WordPress Contact Form Email 1.2.65 CSRF / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Contact Form Email plugin version 1.2.65 suffers from cross site request forgery and cross site scripting vulnerabilities.