Subscribe via feed.
Archive for June, 2019

Sahi Pro 8.x Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sahi Pro version 8.x suffers from a cross site scripting vulnerability.

BlogEngine.NET 3.3.7 Directory Traversal / Remote Code Execution

Posted by deepcore under exploit (No Respond)

BlogEngine.NET versions 3.3.7 and earlier are vulnerable to two separate directory traversal issues that can lead to remote code execution.

[webapps] BlogEngine.NET 3.3.6/3.3.7 – 'theme Cookie' Directory Traversal / Remote Code Execution

Posted by deepcore under Security (No Respond)

BlogEngine.NET 3.3.6/3.3.7 – ‘theme Cookie’ Directory Traversal / Remote Code Execution

Tags: ,

[webapps] BlogEngine.NET 3.3.6/3.3.7 – 'dirPath' Directory Traversal / Remote Code Execution

Posted by deepcore under Security (No Respond)

BlogEngine.NET 3.3.6/3.3.7 – ‘dirPath’ Directory Traversal / Remote Code Execution

Tags: ,

Clever Dog Smart Camera DOG-2W / DOG-2W-V4 File Disclosure / Backdoor

Posted by deepcore under exploit (No Respond)

Clever Dog Smart Camera types DOG-2W and DOG-2W-V4 suffer from file disclosure, default telnet backdoor credential, and insecure transit vulnerabilities.

RedwoodHQ 2.5.5 Authentication Bypass

Posted by deepcore under exploit (No Respond)

RedwoodHQ version 2.5.5 suffers from an authentication bypass vulnerability.

Microsoft Windows UAC Protection Bypass

Posted by deepcore under exploit (No Respond)

This script is a proof of concept to bypass the Microsoft Windows User Access Control (UAC) via SluiFileHandlerHijackLPE.

Spring Security OAuth 2.3 Open Redirection

Posted by deepcore under exploit (No Respond)

Spring Security OAuth versions 2.3 prior to 2.3.6 suffer from open redirection vulnerabilities.

Microsoft Word (2016) Deceptive File Reference

Posted by deepcore under exploit (No Respond)

When a Microsoft Word “.docx” File contains a hyperlink to another file, it will run the first file it finds in that directory with a valid extension. But will present to the end user an extension-less file in its Security warning dialog box without showing the extension type. If another “empty” file of the same […]

HC10 HC.Server Service 10.14 Remote Invalid Pointer Write

Posted by deepcore under exploit (No Respond)

The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS if attackers can reach the service on port 8794. In addition this can potentially be leveraged for post exploit persistence with SYSTEM privileges, if physical access or malware is involved. If a physical attacker or malware can set its own program […]