Subscribe via feed.
Archive for August, 2019

[webapps] TortoiseSVN 1.12.1 – Remote Code Execution

Posted by deepcore under Security (No Respond)

TortoiseSVN 1.12.1 – Remote Code Execution

Tags: ,

[webapps] D-Link DIR-600M – Authentication Bypass (Metasploit)

Posted by deepcore under Security (No Respond)

D-Link DIR-600M – Authentication Bypass (Metasploit)

Tags: ,

[webapps] WordPress Plugin Download Manager 2.5 – Cross-Site Request Forgery

Posted by deepcore under Security (No Respond)

WordPress Plugin Download Manager 2.5 – Cross-Site Request Forgery

Tags: ,

[dos] Windows PowerShell – Unsanitized Filename Command Execution

Posted by deepcore under Security (No Respond)

Windows PowerShell – Unsanitized Filename Command Execution

Tags: ,

[webapps] Joomla! Component JS Jobs (com_jsjobs) 1.2.5 – 'customfields.php' SQL Injection

Posted by deepcore under Security (No Respond)

Joomla! Component JS Jobs (com_jsjobs) 1.2.5 – ‘customfields.php’ SQL Injection

Tags: ,

[webapps] SugarCRM Enterprise 9.0.0 – Cross-Site Scripting

Posted by deepcore under Security (No Respond)

SugarCRM Enterprise 9.0.0 – Cross-Site Scripting

Tags: ,

Ghidra (Linux) 9.0.4 Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

Ghidra (Linux) version 9.0.4 suffers from a .gar related arbitrary code execution vulnerability.

Joomla JS Jobs 1.2.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla JS Jobs component version 1.2.5 suffers from a remote SQL injection vulnerability in cities.php.

Cisco Adaptive Security Appliance Path Traversal

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a security vulnerability in Cisco ASA that would allow an attacker to view sensitive system information without authentication by using directory traversal techniques.

UNA 10.0.0 RC1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

UNA version 10.0.0 RC1 suffers from a persistent cross site scripting vulnerability in polyglot.php.