Subscribe via feed.
Archive for January, 2020

Freelancy 1.0.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Freelancy version 1.0.0 suffers from a remote code execution vulnerability.

Car Rental Project 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Car Rental Project version 1.0 suffers from a remote code execution vulnerability.

Digi AnywhereUSB 14 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Digi AnywhereUSB version 14 suffers from a cross site scripting vulnerability.

Hospital Management System 4.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Hospital Management System version 4.0 suffers from multiple reflective cross site scripting vulnerabilities.

Citrix Application Delivery Controller / Gateway 10.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a remote code execution vulnerability in Citrix Application Delivery Controller and Gateway version 10.5.

VPN Unlimited 6.1 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

VPN Unlimited version 6.1 suffers from an unquoted service path vulnerability.

IBM RICOH InfoPrint 6500 Printer HTML Injection

Posted by deepcore under exploit (No Respond)

The IBM RICOH InfoPrint 6500 printer suffers from an html injection vulnerability.

WordPress 5.3 Denial Of Service

Posted by deepcore under exploit (No Respond)

WordPress is vulnerable to denial of service by abusing XMLRPC API. The system.multicall function lets you batch other API calls. Another API function is pingback.ping, which makes WordPress make a connection out to another site. If you batch a few thousand pingback.ping requests using the multicall feature, you can exhaust a variety of different resources […]

Sagemcom Fast 3890 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This exploit uses the Cable Haunt vulnerability to open a shell for the Sagemcom F@ST 3890 (50_10_19-T1) cable modem. The exploit serves a website that sends a malicious websocket request to the cable modem. The request will overflow a return address in the spectrum analyzer of the cable modem and using a rop chain start […]

Redir 3.3 Denial Of Service

Posted by deepcore under exploit (No Respond)

Redir version 3.3 suffers from a denial of service vulnerability.