Subscribe via feed.
Archive for April, 2019

Microsoft Windows Contact File Format Arbitary Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw is due to processing of contact files.

[webapps] ATutor < 2.2.4 – 'file_manager' Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

ATutor < 2.2.4 – 'file_manager' Remote Code Execution (Metasploit)

Tags: ,

[shellcode] Linux/x86 – Add User to Passwd File Shellcode (149 bytes)

Posted by deepcore under Security (No Respond)

Linux/x86 – Add User to Passwd File Shellcode (149 bytes)

Tags: ,

[local] Microsoft Internet Explorer 11 – XML External Entity Injection

Posted by deepcore under Security (No Respond)

Microsoft Internet Explorer 11 – XML External Entity Injection

Tags: ,

[local] CyberArk EPM 10.2.1.603 – Security Restrictions Bypass

Posted by deepcore under Security (No Respond)

CyberArk EPM 10.2.1.603 – Security Restrictions Bypass

Tags: ,

PHP 7.2 imagecolormatch() Out-Of-Band Heap Write

Posted by deepcore under exploit (No Respond)

PHP version 7.2 suffers from an imagecolormatch() out-of-band heap write vulnerability.

Ashop Shopping Cart Software SQL Injection

Posted by deepcore under exploit (No Respond)

Ashop Shopping Cart Software suffers from a remote SQL injection vulnerability in bannedcustomers.php.

TP-LINK TL-WR940N / TL-WR941ND Buffer Overflow

Posted by deepcore under exploit (No Respond)

TP-LINK models TL-WR940N and TL-WR941ND suffer from a buffer overflow vulnerability.

Loytec LGATE-902 XSS / Traversal / File Deletion

Posted by deepcore under exploit (No Respond)

Loytec LGATE-902 versions prior to 6.4.2 suffer from cross site scripting, arbitrary file deletion, and directory traversal vulnerabilities.

EasyIO 30P Authentication Bypass / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

EasyIO 30P versions prior to 2.0.5.27 suffer from authentication bypass and cross site scripting vulnerabilities.