Subscribe via feed.
Archive for June, 2019

[remote] AROX School-ERP Pro – Unauthenticated Remote Command Execution (Metasploit)

Posted by deepcore under Security (No Respond)

AROX School-ERP Pro – Unauthenticated Remote Command Execution (Metasploit)

Tags: ,

http://www.bayaolocal.go.th

Posted by deepcore under defacement (No Respond)

http://www.bayaolocal.go.th notified by Dev19Feb

Tags:

http://www.paeng.go.th

Posted by deepcore under defacement (No Respond)

http://www.paeng.go.th notified by Dev19Feb

Tags:

http://www.kamkoksoong.go.th

Posted by deepcore under defacement (No Respond)

http://www.kamkoksoong.go.th notified by Dev19Feb

Tags:

Tzumi Electronics Klic Lock Authentication Bypass

Posted by deepcore under exploit (No Respond)

Tzumi Electronics Klic Lock version 1.0.9 allows for attackers to access resources via capture-replay.

Aida64 6.00.5100 SEH Buffer Overflow

Posted by deepcore under exploit (No Respond)

Aida64 version 6.00.5100 Log to CSV File local SEH buffer overflow exploit.

CentOS 7.6 ptrace_scope Privlege Escalation

Posted by deepcore under exploit (No Respond)

CentOS version 7.6 ptrace_scope misconfiguration local privilege escalation exploit.

Thunderbird libical Heap Overflow

Posted by deepcore under exploit (No Respond)

A heap-based buffer overflow has been identified in the Thunderbird email client. The issue is present in the libical implementation, which was forked from upstream libical version 0.47. The issue can be triggered remotely, when an attacker sends an specially crafted calendar attachment and does not require user interaction. It might be used by a […]

Thunderbird libical icalparser.c Heap Overflow

Posted by deepcore under exploit (No Respond)

A heap-based buffer overflow has been identified in the Thunderbird email client. The issue is present in the libical implementation, which was forked from upstream libical version 0.47. The issue can be triggered remotely, when an attacker sends an specially crafted calendar attachment and does not require user interaction. It might be used by a […]

Thunderbird libical Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

A stack-based buffer overflow has been identified in the Thunderbird email client. The issue is present in the libical implementation, which was forked from upstream libical version 0.47. The issue can be triggered remotely, when an attacker sends an specially crafted calendar attachment and does not require user interaction. It might be used by a […]