Subscribe via feed.
Archive for February, 2020

WordPress Wordfence 7.4.6 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Wordfence plugin version 7.4.6 suffers from a cross site scripting vulnerability.

OpenEXR Memory Safety Issues

Posted by deepcore under exploit (No Respond)

OpenEXR suffers from multiple memory safety issues including out-of-bounds access.

WordPress WPForms-Lite 1.5.8.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WPForms-Lite plugin version 1.5.8.2 suffers from a cross site scripting vulnerability.

WordPress Yikes Inc Easy Mailchimp Extender 6.6.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Yikes Inc Easy Mailchimp Extender plugin version 6.6.2 suffers from a cross site scripting vulnerability.

Diamorphine Rootkit Signal Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module uses Diamorphine rootkit’s privesc feature using signal 64 to elevate the privileges of arbitrary processes to UID 0 (root). This module has been tested successfully with Diamorphine from master branch (2019-10-04) on Linux Mint 19 kernel 4.15.0-20-generic (x64).

Apache James Server 2.3.2 Insecure User Creation / Arbitrary File Write

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability that exists due to a lack of input validation when creating a user. Messages for a given user are stored in a directory partially defined by the username. By creating a user with a directory traversal payload as the username, commands can be written to a given directory. To […]

http://ccit.go.th

Posted by deepcore under defacement (No Respond)

http://ccit.go.th notified by ./s3nt1n3L

Tags:

Virtual Freer 1.58 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Virtual Freer version 1.58 suffers from a remote command execution vulnerability.

SmartClient 120 Information Disclosure / XML Injection / LFI / Code Execution

Posted by deepcore under exploit (No Respond)

SmartClient version 120 suffers from information disclosure, local file inclusion, remote file upload, and XML external entity injection vulnerabilities.

Nanometrics Centaur 4.3.23 Memory Leak

Posted by deepcore under exploit (No Respond)

Nanometrics Centaur version 4.3.23 suffers from an unauthenticated remote memory leak vulnerability.