Subscribe via feed.
Archive for August, 2019

Webmin 1.920 password_change.cgi Backdoor

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a backdoor in Webmin versions 1.890 through 1.920. Only the SourceForge downloads were backdoored, but they are listed as official downloads on the project’s site. Unknown attacker(s) inserted Perl qx statements into the build server’s source code on two separate occasions: once in April 2018, introducing the backdoor in the 1.890 […]

Exim 4.91 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a flaw in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to command execution with root privileges.

http://khaophoem.go.th/m-1.html

Posted by deepcore under defacement (No Respond)

http://khaophoem.go.th/m-1.html notified by moncet

Tags:

Valve Says Turning Away Researcher Was A Mistake

Posted by deepcore under exploit (No Respond)

Snapforce CRM 8.3.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Snapforce CRM version 8.3.0 suffers from multiple cross site scripting vulnerabilities.

Wikindx 5.8.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Wikindx version 5.8.2 suffers from a remote SQL injection vulnerability.

Endian Firewall 3.3.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Endian Firewall version 3.3.0 suffers from a cross site scripting vulnerability.

Microsoft Windows SET_REPARSE_POINT_EX Mount Point Security Feature Bypass

Posted by deepcore under exploit (No Respond)

The NTFS driver supports a new FS control code to set a mount point which the existing sandbox mitigation doesn’t support allowing a sandboxed application to set an arbitrary mount point symbolic link.

http://www.djop.go.th/asifa.html

Posted by deepcore under defacement (No Respond)

http://www.djop.go.th/asifa.html notified by ./Mar22

Tags:

Pulse Secure SSL VPN 8.1R15.1 / 8.2 / 8.3 / 9.0 Arbitrary File Disclosure

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits Pulse Secure SSL VPN versions 8.1R15.1, 8.2, 8.3, and 9.0 which suffer from an arbitrary file disclosure vulnerability.