Subscribe via feed.
Archive for August, 2019

Joomla JS Support Ticket 1.1.6 Arbitrary File Deletion

Posted by deepcore under exploit (No Respond)

Joomla JS Support Ticket component version 1.1.6 suffers from an arbitrary file deletion vulnerability in ticket.php.

Webmin 1.920 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary command execution vulnerability in Webmin versions 1.920 and below. If the password change module is turned on, the unauthenticated user can execute arbitrary commands with root privileges.

ManageEngine OpManager 12.4x Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module bypasses the user password requirement in the OpManager versions 12.4.034 and below. It performs authentication bypass and executes commands on the server.

VxWorks 6.8 Integer Underflow

Posted by deepcore under exploit (No Respond)

VxWorks version 6.8 suffers from an integer underflow vulnerability.

ManageEngine OpManager 12.4x Privilege Escalation / Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits SQL injection and command injection vulnerability in the OpManager versions 12.4.034 and below.

BSI Advance Hotel Booking System 2.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

BSI Advance Hotel Booking System version 2.0 suffers from a persistent cross site scripting vulnerability in booking_details.php.

Joomla JS Support Ticket 1.1.6 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla JS Support Ticket component version 1.1.6 suffers from a remote SQL injection vulnerability in ticketreply.php.

ManageEngine Application Manager 14.2 Privilege Escalation / Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits SQL injection and command injection vulnerabilities in the ManageEngine Application Manager versions 14.2 and below.

WebKit Universal Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WebKit suffers from a universal cross site scripting vulnerability via XSLT and nested document replacements.

Steam Windows Client Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Steam Windows client local privilege escalation exploit.