Subscribe via feed.
Archive for November, 2019

FusionPBX Operator Panel exec.php Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authenticated command injection vulnerability in FusionPBX versions 4.4.3 and prior. The exec.php file within the Operator Panel permits users with operator_panel_view permissions, or administrator permissions, to execute arbitrary commands as the web server user by sending a system command to the FreeSWITCH event socket interface. This module has been tested […]

http://inderm.go.th

Posted by deepcore under defacement (No Respond)

http://inderm.go.th notified by Scrub

Tags:

[local] Shrew Soft VPN Client 2.2.2 – 'iked' Unquoted Service Path

Posted by deepcore under Security (No Respond)

Shrew Soft VPN Client 2.2.2 – ‘iked’ Unquoted Service Path

Tags: ,

Technicolor TD5130.2 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Technicolor TD5130.2 with firmware version OI_Fw_V20 suffers from a remote command execution vulnerability.

Technicolor TC7300.B0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Technicolor versions TC7300.B0 through STFA.51.20 suffer from a persistent cross site scripting vulnerability.

Fastweb Fastgate 0.00.81 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Fastweb Fastgate version 0.00.81 suffers from a remote code execution vulnerability.

gSOAP 2.8 Directory Traversal

Posted by deepcore under exploit (No Respond)

gSOAP version 2.8 suffers from a directory traversal vulnerability.

ScanGuard Antivirus Insecure Permissions

Posted by deepcore under exploit (No Respond)

Scanguard versions through 2019-11-12 on Windows has insecure permissions for the installation directory, leading to privilege escalation via a trojan horse executable file.

Siemens Desigo PX 6.00 Denial Of Service

Posted by deepcore under exploit (No Respond)

Siemens Desigo PX version 6.00 remote denial of service exploit.

CMS Made Simple 2.2.8 Remote Code Execution

Posted by deepcore under exploit (No Respond)

An issue was discovered in CMS Made Simple version 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible to reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection. This Metasploit module has been successfully tested on […]