Subscribe via feed.
Archive for June, 2019

Telus Actiontec WEB6000Q Serial Number Information Disclosure

Posted by deepcore under exploit (No Respond)

Telus Actiontec WEB6000Q with firmware 1.1.02.22 suffers from a serial number information disclosure vulnerability. The wireless extenders use DHCP Option 125 to include device details such as model number, manufacturer, and serial number. The WCB6000Q DHCP DISCOVER and REQUEST broadcasts include the device serial number in the DHCP option 125 (subopt 2) field. An attacker […]

Telus Actiontec T2200H Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Telus Actiontec T2200H with firmware T2200H-31.128L.08 suffers from a local privilege escalation vulnerability.

[local] Pronestor Health Monitoring < 8.1.11.0 – Privilege Escalation

Posted by deepcore under Security (No Respond)

Pronestor Health Monitoring < 8.1.11.0 – Privilege Escalation

Tags: ,

[webapps] Sitecore 8.x – Deserialization Remote Code Execution

Posted by deepcore under Security (No Respond)

Sitecore 8.x – Deserialization Remote Code Execution

Tags: ,

[papers] LDAP Swiss Army Knife

Posted by deepcore under Security (No Respond)

LDAP Swiss Army Knife

Tags: ,

[webapps] FusionPBX 4.4.3 – Remote Command Execution

Posted by deepcore under Security (No Respond)

FusionPBX 4.4.3 – Remote Command Execution

Tags: ,

Amcrest IPM-721S Credential Disclosure / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Amcrest IPM-721S suffers from credential disclosure, privilege escalation, and a long list of other vulnerabilities.

Blipcare Clear Text Communication / Memory Corruption

Posted by deepcore under exploit (No Respond)

Blipcare web services suffer from having traffic in clear text, open wifi, and memory corruption vulnerabilities.

Dlink DCS-1130 Command Injection / CSRF / Stack Overflow

Posted by deepcore under exploit (No Respond)

Dlink DCS-1130 suffers from command injection, cross site request forgery, stack overflow, and various other vulnerabilities.

Securifi Almond 2015 Buffer Overflow / Command Injection / XSS / CSRF

Posted by deepcore under exploit (No Respond)

Securifi Almond 2015 suffers from buffer overflow, command injection, cross site scripting, cross site request forgery, and various other vulnerabilities.