Subscribe via feed.
Archive for July, 2019

Microsoft Windows HTTP To SMB NTLM Reflection Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from an HTTP to SMB NTLM reflection that leads to a privilege escalation.

PHP Laravel Framework Token Unserialize Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in the PHP Laravel Framework for versions 5.5.40, 5.6.x up to 5.6.29. Remote command execution is possible via a correctly formatted HTTP X-XSRF-TOKEN header, due to an insecure unserialize call of the decrypt method in Illuminate/Encryption/Encrypter.php. Authentication is not required, however exploitation requires knowledge of the Laravel APP_KEY. Similar […]

AppXSvc Hard Link Privilege Escalation

Posted by deepcore under exploit (No Respond)

There exists a privilege escalation vulnerability for Windows 10 builds prior to build 17763. Due to the AppXSvc’s improper handling of hard links, a user can gain full privileges over a SYSTEM-owned file. The user can then utilize the new file to execute code as SYSTEM. This Metasploit module employs a technique using the Diagnostics […]

[local] R 3.4.4 (Windows 10 x64) – Buffer Overflow SEH (DEP/ASLR Bypass)

Posted by deepcore under Security (No Respond)

R 3.4.4 (Windows 10 x64) – Buffer Overflow SEH (DEP/ASLR Bypass)

Tags: ,

[webapps] FlightPath < 4.8.2 / < 5.0-rc2 – Local File Inclusion

Posted by deepcore under Security (No Respond)

FlightPath < 4.8.2 / < 5.0-rc2 – Local File Inclusion

Tags: ,

[dos] Microsoft Windows Remote Desktop – 'BlueKeep' Denial of Service (Metasploit)

Posted by deepcore under Security (No Respond)

Microsoft Windows Remote Desktop – ‘BlueKeep’ Denial of Service (Metasploit)

Tags: ,

[dos] Android 7 – 9 VideoPlayer – 'ihevcd_parse_pps' Out-of-Bounds Write

Posted by deepcore under Security (No Respond)

Android 7 – 9 VideoPlayer – ‘ihevcd_parse_pps’ Out-of-Bounds Write

Tags: ,

[webapps] CISCO Small Business 200 / 300 / 500 Switches – Multiple Vulnerabilities

Posted by deepcore under Security (No Respond)

CISCO Small Business 200 / 300 / 500 Switches – Multiple Vulnerabilities

Tags: ,

[webapps] NETGEAR WiFi Router JWNR2010v5 / R6080 – Authentication Bypass

Posted by deepcore under Security (No Respond)

NETGEAR WiFi Router JWNR2010v5 / R6080 – Authentication Bypass

Tags: ,

[local] Streamripper 2.6 – 'Song Pattern' Buffer Overflow

Posted by deepcore under Security (No Respond)

Streamripper 2.6 – ‘Song Pattern’ Buffer Overflow

Tags: ,