Subscribe via feed.
Archive for December, 2019

Metasploit Sample Webapp Exploit

Posted by deepcore under exploit (No Respond)

This Metasploit exploit module illustrates how a vulnerability could be exploited in a webapp.

OpenMRS Java Deserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

OpenMRS is an open-source platform that supplies users with a customizable medical record system. There exists an object deserialization vulnerability in the webservices.rest module used in OpenMRS Platform. Unauthenticated remote code execution can be achieved by sending a malicious XML payload to a Rest API endpoint such as /ws/rest/v1/concept. This Metasploit module uses an XML […]

Zendesk SweetHawk Survey 1.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Zendesk SweetHawk Survey version 1.6 suffers from a persistent cross site scripting vulnerability.

NopCommerce 4.2.0 Privilege Escalation

Posted by deepcore under exploit (No Respond)

NopCommerce version 4.2.0 suffers from a privilege escalation vulnerability.

Xerox AltaLink C8035 Printer Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

The Xerox AltaLink C8035 Printer suffers from a cross site request forgery vulnerability.

Tautulli 2.1.9 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Tautulli version 2.1.9 suffers from a cross site request forgery vulnerability.

Serv-U FTP Server 15.1.7 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Serv-U FTP Server version 15.1.7 suffers from a persistent cross site scripting vulnerability leveraging the Email parameter.

Netgear R6400 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Netgear R6400 suffers from a remote code execution vulnerability.

[webapps] Telerik UI – Remote Code Execution via Insecure Deserialization

Posted by deepcore under Security (No Respond)

Telerik UI – Remote Code Execution via Insecure Deserialization

Tags: ,

[remote] OpenMRS – Java Deserialization RCE (Metasploit)

Posted by deepcore under Security (No Respond)

OpenMRS – Java Deserialization RCE (Metasploit)

Tags: ,