Subscribe via feed.
Archive for September, 2019

http://healthws.ntwo.moph.go.th

Posted by deepcore under defacement (No Respond)

http://healthws.ntwo.moph.go.th notified by Goodzilam

Tags:

Ticket-Booking 1.4 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Ticket-Booking version 1.4 suffers from an authentication bypass vulnerability.

College-Management-System 1.2 Authentication Bypass

Posted by deepcore under exploit (No Respond)

College-Management-System version 1.2 suffers from an authentication bypass vulnerability.

Webmin 1.920 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Webmin version 1.920 remote code execution exploit that leverages the vulnerability noted in CVE-2019-15107.

AppXSvc 17763.1.amd64fre.rs5_release.180914-1434 Privilege Escalation

Posted by deepcore under exploit (No Respond)

AppXSvc version 17763.1.amd64fre.rs5_release.180914-1434 suffers from an arbitrary file security descriptor overwrite privilege escalation vulnerability.

docPrint Pro 8.0 SEH Buffer Overflow

Posted by deepcore under exploit (No Respond)

docPrint Pro version 8.0 suffers from a SEH buffer overflow vulnerability.

Inteno IOPSYS Gateway 3DES Key Extraction Improper Access

Posted by deepcore under exploit (No Respond)

Inteno EG200 routers with firmware versions EG200-WU7P1U_ADAMO3.16.4-190226_1650 and below have a JUCI ACL misconfiguration that allows the “user” account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.

LastPass Credential Leak From Previous Site

Posted by deepcore under exploit (No Respond)

LastPass suffers from an issue where bypassing do_popupregister() leaks credentials from the previous site.

[webapps] Symantec Advanced Secure Gateway (ASG) / ProxySG – Unrestricted File Upload

Posted by deepcore under Security (No Respond)

Symantec Advanced Secure Gateway (ASG) / ProxySG – Unrestricted File Upload

Tags: ,

[local] AppXSvc – Privilege Escalation

Posted by deepcore under Security (No Respond)

AppXSvc – Privilege Escalation

Tags: ,