Subscribe via feed.
Archive for March, 2019

Cisco RV320 Unauthenticated Configuration Export

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the configuration of a Cisco RV320 router can still be exported without authentication via the device’s web interface due to an inadequate fix by the vendor.

Cisco RV320 Unauthenticated Diagnostic Data Retrieval

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered that the Cisco RV320 router still exposes sensitive diagnostic data without authentication via the device’s web interface due to an inadequate fix by the vendor.

Cisco RV320 Command Injection

Posted by deepcore under exploit (No Respond)

RedTeam Pentesting discovered a command injection vulnerability in the web-based certificate generator feature of the Cisco RV320 router which was inadequately patched by the vendor.

Fat Free CRM 0.19.0 HTML Injection

Posted by deepcore under exploit (No Respond)

Fat Free CRM version 0.19.0 suffers from an html injection vulnerability.

GnuTLS verify_crt() Use-After-Free

Posted by deepcore under exploit (No Respond)

This is a critical memory corruption vulnerability in any API backed by verify_crt(), including gnutls_x509_trust_list_verify_crt() and related routines in GnuTLS.

SpiderMonkey IonMonkey Type Confusion

Posted by deepcore under exploit (No Respond)

A bug in IonMonkeys type inference system when JIT compiling and entering a constructor function via on-stack replacement (OSR) allows the compilation of JITed functions that cause type confusions between arbitrary objects.

Oracle Weblogic Server Deserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module demonstrates that an unauthenticated attacker with network access to the Oracle Weblogic Server T3 interface can send a serialized object (weblogic.jms.common.StreamMessag eImpl) to the interface to execute code on vulnerable hosts.

CMS Made Simple (CMSMS) Showtime2 File Upload Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a file upload vulnerability that allows for remote command execution in Showtime2 module versions 3.6.2 and below in CMS Made Simple (CMSMS). An authenticated user with “Use Showtime2” privilege could exploit the vulnerability. The vulnerability exists in the Showtime2 module, where the class “class.showtime2_image.php” does not ensure that a watermark file […]

[dos] Microsoft Visio 2016 16.0.4738.1000 – 'Log in accounts' Denial of Service

Posted by deepcore under Security (No Respond)

Microsoft Visio 2016 16.0.4738.1000 – ‘Log in accounts’ Denial of Service

Tags: ,

[remote] CMS Made Simple (CMSMS) Showtime2 – File Upload RCE (Metasploit)

Posted by deepcore under Security (No Respond)

CMS Made Simple (CMSMS) Showtime2 – File Upload RCE (Metasploit)

Tags: ,