Subscribe via feed.
Archive for January, 2020

Trend Micro Security (Consumer) Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

Trend Micro Security can potentially allow an attacker to use a malicious program to escalate privileges to SYSTEM integrity and obtain persistence on a vulnerable system.

WordPress Postie 1.9.40 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Postie plugin versions 1.9.40 and below suffer from a persistent cross site scripting vulnerability.

SunOS 5.10 Generic_147148-26 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

SunOS version 5.10 Generic_147148-26 local privilege escalation exploit. A buffer overflow in the CheckMonitor() function in the Common Desktop Environment versions 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in […]

Online Book Store 1.0 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Online Book Store version 1.0 suffers from an arbitrary file upload vulnerability.

Tautulli 2.1.9 Denial Of Service

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a denial of service vulnerability in Tautulli version 2.1.9.

CurveBall Microsoft Windows CryptoAPI Spoofing Proof Of Concept

Posted by deepcore under exploit (No Respond)

This is a proof of concept exploit that demonstrates the Microsoft Windows CryptoAPI spoofing vulnerability as described in CVE-2020-0601 and disclosed by the NSA.

CurveBall Microsoft Windows CryptoAPI Spoofing Proof Of Concept

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for the Microsoft Windows CurveBall vulnerability where the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. ECC relies on different parameters. These parameters are standardized for many curves. However, Microsoft did not check all these parameters. The parameter G (the generator) was not checked, and the attacker […]

Jenkins Gitlab Hook 1.4.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Jenkins Gitlab Hook plugin version 1.4.2 suffers from a cross site scripting vulnerability.

Citrix ADC / Gateway Path Traversal

Posted by deepcore under exploit (No Respond)

This is an nmap nse script to test for the path traversal vulnerability in Citrix Application Delivery Controller (ADC) and Gateway.

WordPress Resim ara 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Resim ara plugin version 1.0 suffers from a cross site scripting vulnerability.