Subscribe via feed.
Archive for February, 2020

SprintWork 2.3.1 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

SprintWork version 2.3.1 suffers from a local privilege escalation vulnerability.

SweynTooth Bluetooth Exploits

Posted by deepcore under exploit (No Respond)

SweynTooth captures a family of 12 vulnerabilities (more under non-disclosure) across different Bluetooth Low Energy (BLE) software development kits (SDKs) of six major system-on-a-chip (SoC) vendors. The vulnerabilities expose flaws in specific BLE SoC implementations that allow an attacker in radio range to trigger deadlocks, crashes and buffer overflows or completely bypass security depending on […]

WordPress Ultimate-Member 2.1.3 Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Ultimate-Member plugin version 2.1.3 suffers from a local file inclusion vulnerability.

SuiteCRM 7.11.11 Second-Order PHP Object Injection

Posted by deepcore under exploit (No Respond)

SuiteCRM versions 7.11.11 and below suffer from a second-order php object injection vulnerability.

SuiteCRM 7.11.11 Phar Deserialization

Posted by deepcore under exploit (No Respond)

SuiteCRM versions 7.11.11 and below suffer from multiple phar deserialization vulnerabilities.

Pandora FMS 7.0 Authenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

Pandora FMS version 7.0 suffers from an authenticated remote code execution vulnerability.

SuiteCRM 7.11.11 Bean Manipulation

Posted by deepcore under exploit (No Respond)

SuiteCRM versions 7.11.11 and below suffer from an action_saveHTMLField bean manipulation vulnerability.

OpenTFTP 1.66 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

OpenTFTP version 1.66 suffers from a local privilege escalation vulnerability.

SuiteCRM 7.11.11 Broken Access Control / Local File Inclusion

Posted by deepcore under exploit (No Respond)

SuiteCRM versions 7.11.11 and below suffer from an add_to_prospect_list broken access control that allows for local file inclusion attacks.

SuiteCRM 7.11.10 SQL Injection

Posted by deepcore under exploit (No Respond)

SuiteCRM versions 7.11.10 and below suffer from multiple remote SQL injection vulnerabilities.