Subscribe via feed.
Archive for February, 2020

Windscribe WindscribeService Named Pipe Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Windscribe VPN client application for Windows makes use of a Windows service WindscribeService.exe which exposes a named pipe \.pipeWindscribeService allowing execution of programs with elevated privileges. Windscribe versions prior to 1.82 do not validate user-supplied program names, allowing execution of arbitrary commands as SYSTEM. This Metasploit module has been tested successfully on Windscribe versions […]

[dos] AbsoluteTelnet 11.12 – 'license name' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

AbsoluteTelnet 11.12 – ‘license name’ Denial of Service (PoC)

Tags: ,

[webapps] Cisco Data Center Network Manager 11.2.1 – 'LanFabricImpl' Command Injection

Posted by deepcore under Security (No Respond)

Cisco Data Center Network Manager 11.2.1 – ‘LanFabricImpl’ Command Injection

Tags: ,

[dos] AbsoluteTelnet 11.12 – "license name" Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

AbsoluteTelnet 11.12 – “license name” Denial of Service (PoC)

Tags: ,

[webapps] Cisco Data Center Network Manager 11.2.1 – 'getVmHostData' SQL Injection

Posted by deepcore under Security (No Respond)

Cisco Data Center Network Manager 11.2.1 – ‘getVmHostData’ SQL Injection

Tags: ,

[webapps] Online Job Portal 1.0 – 'user_email' SQL Injection

Posted by deepcore under Security (No Respond)

Online Job Portal 1.0 – ‘user_email’ SQL Injection

Tags: ,

[dos] VIM 8.2 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

VIM 8.2 – Denial of Service (PoC)

Tags: ,

[webapps] Cisco Data Center Network Manager 11.2 – Remote Code Execution

Posted by deepcore under Security (No Respond)

Cisco Data Center Network Manager 11.2 – Remote Code Execution

Tags: ,

[webapps] Ecommerce Systempay 1.0 – Production KEY Brute Force

Posted by deepcore under Security (No Respond)

Ecommerce Systempay 1.0 – Production KEY Brute Force

Tags: ,

[webapps] Online Job Portal 1.0 – Cross Site Request Forgery (Add User)

Posted by deepcore under Security (No Respond)

Online Job Portal 1.0 – Cross Site Request Forgery (Add User)

Tags: ,