Subscribe via feed.
Archive for March, 2019

Microsoft Windows .Reg File / Dialog Box Message Spoofing

Posted by deepcore under exploit (No Respond)

The Windows registry editor allows specially crafted .reg filenames to spoof the default registry dialog warning box presented to an end user. This can potentially trick unsavvy users into choosing the wrong selection shown on the dialog box. Furthermore, we can deny the registry editor its ability to show the default secondary status dialog box […]

Core FTP 2.0 Build 653 PBSZ Denial Of Service

Posted by deepcore under exploit (No Respond)

Core FTP version 2.0 build 653 suffers from a PBSZ command denial of service vulnerability.

PilusCart 1.4.1 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

PilusCart version 1.4.1 suffers from a cross site request forgery vulnerability.

elFinder PHP Connector exiftran Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in elFinder versions prior to 2.1.48. The PHP connector component allows unauthenticated users to upload files and perform file modification operations, such as resizing and rotation of an image. The file name of uploaded files is not validated, allowing shell metacharacters. When performing image operations on JPEG […]

Unpatched Windows Bug Allows Attackers To Spoof Security Dialog Boxes

Posted by deepcore under exploit (No Respond)

[webapps] WordPress Plugin GraceMedia Media Player 1.0 – Local File Inclusion

Posted by deepcore under Security (No Respond)

WordPress Plugin GraceMedia Media Player 1.0 – Local File Inclusion

Tags: ,

[dos] Core FTP Server FTP / SFTP Server v2 Build 674 – 'MDTM' Directory Traversal

Posted by deepcore under Security (No Respond)

Core FTP Server FTP / SFTP Server v2 Build 674 – ‘MDTM’ Directory Traversal

Tags: ,

[dos] Microsoft Windows – .reg File / Dialog Box Message Spoofing

Posted by deepcore under Security (No Respond)

Microsoft Windows – .reg File / Dialog Box Message Spoofing

Tags: ,

[dos] Core FTP Server FTP / SFTP Server v2 Build 674 – 'SIZE' Directory Traversal

Posted by deepcore under Security (No Respond)

Core FTP Server FTP / SFTP Server v2 Build 674 – ‘SIZE’ Directory Traversal

Tags: ,

MeteoTemplate 17.1 Nectarine Diary 4.0 Open Redirection

Posted by deepcore under exploit (No Respond)

MeteoTemplate version 17.1 with Nectarine Diary plugin version 4.0 suffers from an open redirection vulnerability.