Subscribe via feed.
Archive for January, 2020

Torrent 3GP Converter 1.51 Stack Overflow

Posted by deepcore under exploit (No Respond)

Torrent 3GP Converter version 1.51 suffers from a stack overflow vulnerability.

SolarWinds n-Central Dumpster Diver

Posted by deepcore under exploit (No Respond)

This application, known as the SolarWinds n-Central Dumpster Diver, utilizes the nCentral agent dot net libraries to simulate the agent registration and pull the agent/appliance configuration settings. This information can contain plain text active directory domain credentials. This was reported to SolarWinds PSIRT(psirt@solarwinds.com) on 10/10/2019. In most cases the agent download URL is not secured […]

FusionAuth 1.10 Remote Command Execution

Posted by deepcore under exploit (No Respond)

FusionAuth versions 1.10 and below suffer from a remote command execution vulnerability. An authenticated attacker with enough privileges to access the template editing functions (either site templates or e-mail templates) in the FusionAuth dashboard can execute commands on the underlying operating system using the Apache FreeMarker Expression language.

IceWarp WebMail 11.4.4.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

IceWarp WebMail versions 11.4.4.1 and below suffer from a cross site scripting vulnerability.

macOS / iOS ImageIO Heap Corruption

Posted by deepcore under exploit (No Respond)

macOS and iOS suffers from an ImageIO heap corruption vulnerability when processing malformed TIFF images.

Adive Framework 2.0.8 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Adive Framework version 2.0.8 suffers from a cross site request forgery vulnerability.

Centreon 19.10.5 Credential Disclosure

Posted by deepcore under exploit (No Respond)

Centreon version 19.10.5 suffers from a database credential disclosure vulnerability.

Centreon 19.10.5 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Centreon version 19.10.5 suffers from a remote command execution vulnerability.

Octeth Oempro 4.8 SQL Injection

Posted by deepcore under exploit (No Respond)

Octeth Oempro version 4.8 suffers from a remote SQL injection vulnerability.

[webapps] Centreon 19.10.5 – 'Pollers' Remote Command Execution

Posted by deepcore under Security (No Respond)

Centreon 19.10.5 – ‘Pollers’ Remote Command Execution

Tags: ,