Subscribe via feed.
Archive for March, 2019

Microsoft Windows IE11 VBScript Execution Policy Bypass In MSHTML

Posted by deepcore under exploit (No Respond)

MSHTML only checks for the CLSID associated with VBScript when blocking in the Internet Zone, but doesn’t check other VBScript CLSIDs which allow a web page to bypass the security zone policy.

Chrome StoragePartitionService Double-Destruction Race

Posted by deepcore under exploit (No Respond)

There’s a race condition in the destruction of the BindingState for bindings to the StoragePartitionService in Chrome. It looks like the root cause of the issue is that since we can get two concurrent calls to callbacks returned from mojo::BindingSet::GetBadMessageCallback() from the same BindingSet, which results in a data race destroying the same BindingState.

JFrog Artifactory Pro 6.5.9 Signature Validation

Posted by deepcore under exploit (No Respond)

The SAML SSO addon in JFrog Artifactory version 6.5.9 does not properly validate the XML signature in the SAMLResponse field send to the URL /webapp/saml/loginResponse. An attacker can use this flaw to login as any user if they already can login as some user.

VBScript VbsErase Memory Corruption

Posted by deepcore under exploit (No Respond)

There is an issue in VBScript in the VbsErase function. In some cases, VbsErase fails to clear the argument variable properly, which can trivially lead to crafting a variable with the array type, but with a pointer controlled controlled by an attacker.

Microsoft Edge Flash click2play Bypass

Posted by deepcore under exploit (No Respond)

Microsoft Edge suffers from a Flash click2play bypass with CObjectElement::FinalCreateObject.

PHP MySQLi Database Class 2.9.2 SQL Injection

Posted by deepcore under exploit (No Respond)

PHP MySQLi Database Class version 2.9.2 which is from joshcam suffers from a remote SQL injection vulnerability.

CSZ CMS 1.2.1 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

CSZ CMS version 1.2.1 suffers from an arbitrary file upload vulnerability.

WordPress FormCraft 2.0 CSRF / Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress version 5.0.4 with FormCraft plugin version 2.0 suffers from a cross site request forgery vulnerability that can be leveraged to perform a shell upload.

WinMPG Video Convert 9.3.5 Denial Of Service

Posted by deepcore under exploit (No Respond)

WinMPG Video Convert versions 9.3.5 and below suffer from a local denial of service vulnerability.

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 Denial Of Service

Posted by deepcore under exploit (No Respond)

WinAVI iPod/3GP/MP4/PSP Converter version 4.4.2 suffers from a local denial of service vulnerability.