Subscribe via feed.
Archive for January, 2020

Reliable Datagram Sockets (RDS) rds_atomic_free_op Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module attempts to gain root privileges on Linux systems by abusing a NULL pointer dereference in the rds_atomic_free_op function in the Reliable Datagram Sockets (RDS) kernel module (rds.ko). Successful exploitation requires the RDS kernel module to be loaded. If the RDS module is not blacklisted (default); then it will be loaded automatically. This […]

D-Link DIR-859 Unauthenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

D-Link DIR-859 Routers are vulnerable to OS command injection via the UPnP interface. The vulnerability exists in /gena.cgi (function genacgi_main() in /htdocs/cgibin), which is accessible without credentials.

[remote] Pachev FTP Server 1.0 – Path Traversal

Posted by deepcore under Security (No Respond)

Pachev FTP Server 1.0 – Path Traversal

Tags: ,

[webapps] qdPM 9.1 – Remote Code Execution

Posted by deepcore under Security (No Respond)

qdPM 9.1 – Remote Code Execution

Tags: ,

[dos] BOOTP Turbo 2.0 – Denial of Service (SEH)(PoC)

Posted by deepcore under Security (No Respond)

BOOTP Turbo 2.0 – Denial of Service (SEH)(PoC)

Tags: ,

Microsoft Zero Day Actively Exploited, Patch Forthcoming

Posted by deepcore under exploit (No Respond)

WordPress WP Fanzone 3.1 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress WP Fanzone theme version 3.1 suffers from a remote SQL injection vulnerability.

Neowise CarbonFTP 1.4 Insecure Proprietary Password Encryption

Posted by deepcore under exploit (No Respond)

Neowise CarbonFTP version 1.4 suffers from an insecure proprietary password encryption implementation.

[dos] KeePass 2.44 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

KeePass 2.44 – Denial of Service (PoC)

Tags: ,

[webapps] Citrix XenMobile Server 10.8 – XML External Entity Injection

Posted by deepcore under Security (No Respond)

Citrix XenMobile Server 10.8 – XML External Entity Injection

Tags: ,