Subscribe via feed.
Archive for October, 2019

WebKit WebCore::ReplacementFragment::ReplacementFragment User-Agent Shadow Root Leak

Posted by deepcore under exploit (No Respond)

WebKit suffers from a user-agent shadow root leak in WebCore::ReplacementFragment::ReplacementFragment.

WebKit Cached Pages Universal Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WebKit suffers from a universal cross site scripting vulnerability using cached pages.

DOUBLEPULSAR Payload Execution / Neutralization

Posted by deepcore under exploit (No Respond)

This Metasploit module executes a Metasploit payload against the Equation Group’s DOUBLEPULSAR implant for SMB as popularly deployed by ETERNALBLUE. While this module primarily performs code execution against the implant, the “Neutralize implant” target allows you to disable the implant.

Rocket.Chat Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Rocket.Chat versions prior to 2.1.0 suffer from a cross site scripting vulnerability.

Fortinet FortiSIEM 5.0 / 5.2.1 Improper Certification Validation

Posted by deepcore under exploit (No Respond)

A FortiSIEM collector connects to a Supervisor/Worker over HTTPS TLS (443/TCP) to register itself as well as relaying event data such as syslog, netflow, SNMP, etc. When the Collector (the client) connects to the Supervisor/Worker (the server), the client does not validate the server-provided certificate against its root-CA store. Since the client does no server […]

LG-ERICSSON LN202-003H HomeHub Router Remote Configuration Disclosure

Posted by deepcore under exploit (No Respond)

LG-ERICSSON LN202-003H HomeHub router remote configuration disclosure exploit.

Packet Storm New Exploits For September, 2019

Posted by deepcore under exploit (No Respond)

This archive contains all of the 160 exploits added to Packet Storm in September, 2019.

[remote] DOUBLEPULSAR – Payload Execution and Neutralization (Metasploit)

Posted by deepcore under Security (No Respond)

DOUBLEPULSAR – Payload Execution and Neutralization (Metasploit)

Tags: ,

[webapps] Detrix EDMS 1.2.3.1505 – SQL Injection

Posted by deepcore under Security (No Respond)

Detrix EDMS 1.2.3.1505 – SQL Injection

Tags: ,

https://buriram4.go.th//zx.htm

Posted by deepcore under defacement (No Respond)

https://buriram4.go.th//zx.htm notified by Zarox~Ztayli

Tags: