Subscribe via feed.
Archive for March, 2020

WordPress Tutor LMS 1.5.3 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WordPress Tutor LMS plugin version 1.5.3 suffers from a cross site request forgery vulnerability.

TP-Link TL-WR849N 0.9.1 4.16 Authentication Bypass

Posted by deepcore under exploit (No Respond)

TP-Link TL-WR849N version 0.9.1 4.16 suffers from a firmware upload authentication bypass vulnerability.

Cyberoam Authentication Client 2.1.2.7 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Cyberoam Authentication Client version 2.1.2.7 suffers from a buffer overflow vulnerability.

Netis WF2419 2.2.36123 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Netis WF2419 version 2.2.36123 suffers from a remote code execution vulnerability.

Intelbras Wireless N 150Mbps WRN240 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Intelbras Wireless N 150Mbps WRN240 suffers from a configuration upload authentication bypass vulnerability.

Wing FTP Server 6.2.3 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Wing FTP Server version 6.2.3 suffers from a privilege escalation vulnerability.

Microsoft Exchange 2019 15.2.221.12 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Exchange 2019 version 15.2.221.12 suffers from an authenticated remote code execution vulnerability.

Cacti 1.2.8 Unauthenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie if a guest user has the graph real-time privilege.

JSC DFG ObjectAllocationSinkingPhase Crash

Posted by deepcore under exploit (No Respond)

An issue in JSC leaves the data flow graph inconsistent. While fuzzing JavaScriptCore with fuzzilli, the researcher found a crash condition in JSC.

macOS / iOS ImageIO OpenEXR Image Processing Memory Issues

Posted by deepcore under exploit (No Respond)

macOS and iOS have a vulnerability with ImageIO where memory safety issues occur when processing OpenEXR images.