Subscribe via feed.
Archive for March, 2019

Apache Tika Server Command Injection

Posted by deepcore under exploit (No Respond)

Apache Tika Server versions prior to 1.18 suffer from a command injection vulnerability.

ntopng 3.8.190307 Community Edition Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ntopng version 3.8.190307 Community Edition suffers from a cross site scripting vulnerability.

Intel Modular Server System 10.18 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Intel Modular Server System version 10.18 cross site request forgery change administrative password exploit.

[webapps] Pegasus CMS 1.0 – 'extra_fields.php' Plugin Remote Code Execution

Posted by deepcore under Security (No Respond)

Pegasus CMS 1.0 – ‘extra_fields.php’ Plugin Remote Code Execution

Tags: ,

[webapps] Intel Modular Server System 10.18 – Cross-Site Request Forgery (Change Admin Password)

Posted by deepcore under Security (No Respond)

Intel Modular Server System 10.18 – Cross-Site Request Forgery (Change Admin Password)

Tags: ,

[remote] Apache UNO / LibreOffice Version: 6.1.2 / OpenOffice 4.1.6 API – Remote Code Execution

Posted by deepcore under Security (No Respond)

Apache UNO / LibreOffice Version: 6.1.2 / OpenOffice 4.1.6 API – Remote Code Execution

Tags: ,

[remote] FTPGetter Standard 5.97.0.177 – Remote Code Execution

Posted by deepcore under Security (No Respond)

FTPGetter Standard 5.97.0.177 – Remote Code Execution

Tags: ,

CoreFTP Server FTP / SFTP Server 2 Build 674 MDTM Directory Traversal

Posted by deepcore under exploit (No Respond)

CoreFTP Server FTP and SFTP Server version 2 build 674 suffer from a directory traversal vulnerability. By utilizing a directory traversal along with the FTP MDTM command, an attacker can browse outside the root directory to determine if a file exists based on return file size along with the date the file was last modified […]

WordPress WP Fastest Cache 0.8.9.0 Arbitrary File Deletion

Posted by deepcore under exploit (No Respond)

WordPress WP Fastest Cache plugin versions 0.8.9.0 and below suffer from an arbitrary file deletion vulnerability.

NREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

BEopt suffers from a DLL Hijacking issue. The vulnerability is caused due to the application loading libraries (sdl2.dll and libegl.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into opening a related application file .BEopt located on a remote WebDAV or SMB share. Version 2.8.0 is affected.