Subscribe via feed.
Archive for March, 2019

MeteoTemplate 17.1 Nectarine globalSnow 1.1 Open Redirection

Posted by deepcore under exploit (No Respond)

MeteoTemplate version 17.1 with Nectarine globalSnow plugin version 1.1 suffers from an open redirection vulnerability.

Meteotemplate 17.1 Nectarine indoorData 4.0 Open Redirection

Posted by deepcore under exploit (No Respond)

Meteotemplate version 17.1 with Nectarine indoorData plugin version 4.0 suffers from an open redirection vulnerability.

TeamCity Disabled Registration Bypass

Posted by deepcore under exploit (No Respond)

TeamCity versions prior to 9.0.2 disable registration bypass exploit.

DirectAdmin 1.55 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

DirectAdmin version 1.55 suffers from a cross site request forgery vulnerability.

McAfee ePO 5.9.1 Registered Executable Local Access Bypass

Posted by deepcore under exploit (No Respond)

McAfee ePO version 5.9.1 suffers from a local access bypass vulnerability.

Sony PlayStation 4 WebKit Code Execution

Posted by deepcore under exploit (No Respond)

Sony PlayStation 4 (PS4) versions prior to 6.20 webkit code execution proof of concept exploit.

Flexpaper 2.3.6 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Whitepaper discussing Flexpaper versions 2.3.6 and below which suffer from a remote code execution vulnerability.

OpenKM Document Management Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module allows the execution of remote commands on the server by creating a malicious JSP file. Module has been tested successfully with OpenKM DM between 6.3.2 and 6.3.7 on Debian 4.9.18-1kali1 system. There is also the possibility of working in lower versions.

NetSetMan 4.7.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

NetSetMan version 4.7.1 SEH unicode local buffer overflow exploit.

PRTG Network Monitor 18.2.38 Remote Code Execution

Posted by deepcore under exploit (No Respond)

PRTG Network Monitor version 18.2.38 authenticated remote code execution exploit.