Subscribe via feed.
Archive for December, 2019

http://www.hrm.m-society.go.th/kurd.html

Posted by deepcore under defacement (No Respond)

http://www.hrm.m-society.go.th/kurd.html notified by 0x1998

Tags:

WordPress Scoutnet Kalender 1.1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Scoutnet Kalender plugin version 1.1.0 suffers from a cross site scripting vulnerability.

Inim Electronics SmartLiving SmartLAN/G/SI 6.x Remote Root

Posted by deepcore under exploit (No Respond)

Inim Electronics SmartLiving SmartLAN/G/SI versions 6.x and below suffer from a remote root command execution vulnerability.

Inim Electronics Smartliving SmartLAN/G/SI 6.x SSRF

Posted by deepcore under exploit (No Respond)

Inim Electronics Smartliving SmartLAN/G/SI versions 6.x and below suffer from an unauthenticated server-side request forgery vulnerability.

Inim Electronics Smartliving SmartLAN/G/SI 6.x Hard-Coded Credentials

Posted by deepcore under exploit (No Respond)

Inim Electronics Smartliving SmartLAN/G/SI versions 6.x and below suffer from a hard-coded credential vulnerability.

Apache Olingo OData 4.6.x XML Injection

Posted by deepcore under exploit (No Respond)

Apache Olingo OData versions 4.x.x through 4.6.x suffer from an XML external entity injection vulnerability.

DAViCal CalDAV Server 1.1.8 Persistent Cross Site Scripting

Posted by deepcore under exploit (No Respond)

DAViCal CalDAV Server versions 1.1.8 and below suffer from a persistent cross site scripting vulnerability.

DAViCal CalDAV Server 1.1.8 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

DAViCal CalDAV Server versions 1.1.8 and below suffer from a cross site request forgery vulnerability.

DAViCal CalDAV Server 1.1.8 Reflective Cross Site Scripting

Posted by deepcore under exploit (No Respond)

DAViCal CalDAV Server versions 1.1.8 and below suffer from a reflective cross site scripting vulnerability.

vBulletin 5.5.4 Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits vBulletin versions 5.x through 5.5.4 leveraging a remote command execution vulnerability via the widgetConfig[code] parameter in an ajax/render/widget_php routestring POST request.