Subscribe via feed.
Archive for April, 2019

Horde Form Shell Upload

Posted by deepcore under exploit (No Respond)

Horde Groupware Webmail contains a flaw that allows an authenticated remote attacker to execute arbitrary PHP code. The exploitation requires the Turba subcomponent to be installed. This module was tested on Horde versions 5.2.22 and 5.2.17 running Horde Form subcomponent versions prior to 2.0.19.

Jobgator SQL Injection

Posted by deepcore under exploit (No Respond)

Jobgator suffers from a remote SQL injection vulnerability. Affects the latest version available as of March 5, 2019.

ShoreTel Connect ONSITE Cross Site Scripting / Session Fixation

Posted by deepcore under exploit (No Respond)

ShoreTel Connect ONSITE versions prior to 19.49.1500.0 suffer from cross site scripting and session fixation vulnerabilities.

FlexHEX 2.71 Buffer Overflow

Posted by deepcore under exploit (No Respond)

FlexHEX version 2.71 SEH buffer overflow exploit.

Bolt CMS 3.6.6 Cross Site Request Forgery / Code Execution

Posted by deepcore under exploit (No Respond)

Bolt CMS version 3.6.6 suffers from cross site request forgery and code execution vulnerabilities.

River Past Cam Do 3.7.6 Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

River Past Cam Do version 3.7.6 suffers from an activation code local buffer overflow vulnerability.

WordPress Limit Login Attempts Reloaded 2.7.4 Bypass

Posted by deepcore under exploit (No Respond)

WordPress Limit Login Attempts Reloaded plugin version 2.7.4 suffers from a login limit bypass vulnerability.

AllPlayer 7.4 SEH Buffer Overflow

Posted by deepcore under exploit (No Respond)

AllPlayer version 7.4 SEH unicode buffer overflow exploit.

CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CentOS Web Panel versions 0.9.8.793 (Free) and 0.9.8.753 (Pro) suffer from an email field persistent cross site scripting vulnerability.

CARPE (DIEM) Apache 2.4.x Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Apache versions 2.4.17 up to 2.4.38 apache2ctl graceful logrotate local privilege escalation exploit.