Subscribe via feed.
Archive for April, 2019

NSauditor 3.1.2.0 Community Denial Of Service

Posted by deepcore under exploit (No Respond)

NSauditor version 3.1.2.0 Community denial of service proof of concept exploit.

NSauditor 3.1.2.0 Name Denial Of Service

Posted by deepcore under exploit (No Respond)

NSauditor version 3.1.2.0 Name denial of service proof of concept exploit.

Apache Pluto 3.0.0 / 3.0.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Apache Pluto versions 3.0.0 and 3.0.1 suffer from a persistent cross site scripting vulnerability.

Sierra Wireless AirLink ES450 ACEManager iplogging.cgi Command Injection

Posted by deepcore under exploit (No Respond)

An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this vulnerability.

Sierra Wireless AirLink ES450 ACEManager upload.cgi Unverified Password Change

Posted by deepcore under exploit (No Respond)

An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Sierra Wireless AirLink ES450 ACEManager upload.cgi Remote Code Execution

Posted by deepcore under exploit (No Respond)

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Sierra Wireless AirLink ES450 ACEManager ping_result.cgi Cross Site Scripting

Posted by deepcore under exploit (No Respond)

An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the execution of javascript code running on the victim’s browser. An attacker can get a victim to click a link, or embedded URL, […]

Sierra Wireless AirLink ES450 SNMPD Hard-Coded Credentials

Posted by deepcore under exploit (No Respond)

A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in a hard-coded, in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.

Sierra Wireless AirLink ES450 ACEManager Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on […]

Sierra Wireless AirLink ES450 ACEManager Information Disclosure

Posted by deepcore under exploit (No Respond)

An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.