Subscribe via feed.
Archive for March, 2019

Apple Security Advisory 2019-3-25-6

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2019-3-25-6 – iCloud for Windows 7.11 is now available and addresses buffer overflow, code execution, and cross site scripting vulnerabilities.

Tags: , ,

X-NetStat Pro 5.63 Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

X-NetStat Pro version 5.63 local buffer overflow exploit with egghunter.

Jettweb PHP Hazir Haber Sitesi Scripti 1 SQL Injection

Posted by deepcore under exploit (No Respond)

Jettweb PHP Hazir Haber Sitesi Scripti version 1 suffers from multiple remote SQL injection vulnerabilities.

WordPress Plugins Open Redirection 2019/03/25

Posted by deepcore under exploit (No Respond)

Five WordPress plugins suffer from open redirection vulnerabilities. Affected includes The-CL-Amazon-Thingy plugin version 1.0, Google Document Embedder version 2.5.8, VJ-Slider version 1.0, WPUSW plugin version 1.0, and Angsumans Translator Gold version 2.3.

Jettweb PHP Hazir Haber Sitesi Scripti 2 SQL Injection

Posted by deepcore under exploit (No Respond)

Jettweb PHP Hazir Haber Sitesi Scripti version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Jettweb PHP Hazir Haber Sitesi Scripti 3 SQL Injection

Posted by deepcore under exploit (No Respond)

Jettweb PHP Hazir Haber Sitesi Scripti version 3 suffers from multiple remote SQL injection vulnerabilities.

VMware Host VMX Process Impersonation Hijack Privilege Escalation

Posted by deepcore under exploit (No Respond)

The VMX process (vmware-vmx.exe) process configures and hosts an instance of VM. As is common with desktop virtualization platforms the VM host usually has privileged access into the OS such as mapping physical memory which represents a security risk. To mitigate this the VMX process is created with an elevated integrity level by the authentication […]

VMware Host VMX Process COM Class Hijack Privilege Escalation

Posted by deepcore under exploit (No Respond)

The VMX process (vmware-vmx.exe) process configures and hosts an instance of VM. As is common with desktop virtualization platforms the VM host usually has privileged access into the OS such as mapping physical memory which represents a security risk. To mitigate this the VMX process is created with an elevated integrity level by the authentication […]

Zeeways Matrimony CMS SQL Injection

Posted by deepcore under exploit (No Respond)

Zeeways Matrimony CMS suffers from a remote SQL injection vulnerability.

Zeeways Jobsite CMS SQL Injection

Posted by deepcore under exploit (No Respond)

Zeeways Jobsite CMS suffers from a remote SQL injection vulnerability.