Subscribe via feed.
Archive for August, 2019

http://cco.mof.go.th

Posted by deepcore under defacement (No Respond)

http://cco.mof.go.th notified by EvLaT_

Tags:

ATutor 2.2.4 Backup Remote Command Execution

Posted by deepcore under exploit (No Respond)

ATutor version 2.2.4 suffers from a backup functionality remote command execution vulnerability.

Opencart 2.3.0.2 Insecure OCMod Generation Remote Command Execution

Posted by deepcore under exploit (No Respond)

Opencart versions 2.3.0.2 and below suffer from an insecure OCMod generation remote command execution vulnerability.

ATutor 2.2.4 Arbitrary File Upload / Command Execution

Posted by deepcore under exploit (No Respond)

ATutor version 2.2.4 suffers from a language_import arbitrary file upload that allows for command execution.

KDE 4/5 KDesktopFile Command Injection

Posted by deepcore under exploit (No Respond)

KDE 4/5 is vulnerable to a command injection vulnerability in the KDesktopFile class. When a .desktop or .directory file is instantiated, it unsafely evaluates environment variables and shell expansions using KConfigPrivate::expandString() via the KConfigGroup::readEntry() function. Using a specially crafted .desktop file a remote user could be compromised by simply downloading and viewing the file in […]

iMessage URL Deserializing Heap Overflow

Posted by deepcore under exploit (No Respond)

iMessage suffers from a heap overflow vulnerability when deserializing a URL. This affects Macs only.

CentOS Control Web Panel 0.9.8.836 Remote Command Execution

Posted by deepcore under exploit (No Respond)

CentOS Control Web Panel (CWP) version 0.9.8.836 suffers from a remote command execution vulnerability.

CentOS Control Web Panel 0.9.8.840 User Enumeration

Posted by deepcore under exploit (No Respond)

CentOS Control Web Panel (CWP) versions 0.9.8.836 through 0.9.8.840 suffer from a user enumeration vulnerability.

CentOS Control Web Panel 0.9.8.846 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

CentOS Control Web Panel (CWP) version 0.9.8.846 suffers from a reflective cross site scripting vulnerability.

Active PHP Bookmarks 1.3 SQL Injection

Posted by deepcore under exploit (No Respond)

Active PHP Bookmarks version 1.3 suffer from a cookie_auth error-based remote SQL injection vulnerability.