Subscribe via feed.
Archive for February, 2020

aSc TimeTables 2020.11.4 Denial Of Service

Posted by deepcore under exploit (No Respond)

aSc TimeTables version 2020.11.4 suffers from a denial of service vulnerability.

WordPress WooCommerce CardGate Payment Gateway 3.1.15 Bypass

Posted by deepcore under exploit (No Respond)

WordPress WooCommerce CardGate Payment Gateway plugin version 3.1.15 suffers from a payment process bypass vulnerability.

Magento WooCommerce CardGate Payment Gateway 2.0.30 Bypass

Posted by deepcore under exploit (No Respond)

Magento WooCommerce CardGate Payment Gateway version 2.0.30 suffers from a payment process bypass vulnerability.

Odin Secure FTP Expert 7.6.3 Denial Of Service

Posted by deepcore under exploit (No Respond)

Odin Secure FTP Expert version 7.6.3 suffers from a denial of service vulnerability.

Astak CM-818T3 Remote Configuration Disclosure

Posted by deepcore under exploit (No Respond)

Astak CM-818T3 2.4GHz wireless security surveillance camera remote configuration disclosure exploit.

OpenSMTPD Local Information Disclosure

Posted by deepcore under exploit (No Respond)

Qualys discovered a minor vulnerability in OpenSMTPD, OpenBSD’s mail server. An unprivileged local attacker can read the first line of an arbitrary file (for example, root’s password hash in /etc/master.passwd) or the entire contents of another user’s file (if this file and /var/spool/smtpd/ are on the same filesystem). A proof of concept exploit is included […]

OpenSMTPD Out-Of-Bounds Read

Posted by deepcore under exploit (No Respond)

Qualys discovered a vulnerability in OpenSMTPD, OpenBSD’s mail server. This vulnerability, an out-of-bounds read introduced in December 2015, is exploitable remotely and leads to the execution of arbitrary shell commands.

[remote] OpenSMTPD 6.6.3 – Arbitrary File Read

Posted by deepcore under Security (No Respond)

OpenSMTPD 6.6.3 – Arbitrary File Read

Tags: ,

[webapps] PhpIX 2012 Professional – 'id' SQL Injection

Posted by deepcore under Security (No Respond)

PhpIX 2012 Professional – ‘id’ SQL Injection

Tags: ,

[dos] Core FTP LE 2.2 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

Core FTP LE 2.2 – Denial of Service (PoC)

Tags: ,