Subscribe via feed.
Archive for March, 2020

SQL Server Reporting Services (SSRS) ViewState Deserialization

Posted by deepcore under exploit (No Respond)

A vulnerability exists within Microsoft’s SQL Server Reporting Services which can allow an attacker to craft an HTTP POST request with a serialized object to achieve remote code execution. The vulnerability is due to the fact that the serialized blob is not signed by the server.

[webapps] Centos WebPanel 7 – 'term' SQL Injection

Posted by deepcore under Security (No Respond)

Centos WebPanel 7 – ‘term’ SQL Injection

Tags: ,

[local] AnyBurn 4.8 – Buffer Overflow (SEH)

Posted by deepcore under Security (No Respond)

AnyBurn 4.8 – Buffer Overflow (SEH)

Tags: ,

Wing FTP Server 6.2.3 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Wing FTP Server version 2.3 suffers from a cross site request forgery vulnerability.

ASUS AXSP 1.02.00 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

ASUS AXSP version 1.02.00 suffers from an asComSvc unquoted service path vulnerability.

WordPress Search Meter 2.13.2 CSV Injection

Posted by deepcore under exploit (No Respond)

WordPress Search Meter plugin version 2.13.2 suffers from a CSV injection vulnerability.

[webapps] rConfig 3.93 – 'ajaxAddTemplate.php' Authenticated Remote Code Execution

Posted by deepcore under Security (No Respond)

rConfig 3.93 – ‘ajaxAddTemplate.php’ Authenticated Remote Code Execution

Tags: ,

[webapps] WordPress Plugin Appointment Booking Calendar 1.3.34 – CSV Injection

Posted by deepcore under Security (No Respond)

WordPress Plugin Appointment Booking Calendar 1.3.34 – CSV Injection

Tags: ,

[webapps] Joomla! Component com_newsfeeds 1.0 – 'feedid' SQL Injection

Posted by deepcore under Security (No Respond)

Joomla! Component com_newsfeeds 1.0 – ‘feedid’ SQL Injection

Tags: ,

[webapps] WatchGuard Fireware AD Helper Component 5.8.5.10317 – Credential Disclosure

Posted by deepcore under Security (No Respond)

WatchGuard Fireware AD Helper Component 5.8.5.10317 – Credential Disclosure

Tags: ,