Subscribe via feed.
Archive for April, 2020

Atomic Alarm Clock 6.3 Stack Overflow

Posted by deepcore under exploit (No Respond)

Atomic Alarm Clock version 6.3 unicode SEH stack overflow exploit.

ALLPlayer 7.6 Buffer Overflow

Posted by deepcore under exploit (No Respond)

ALLPlayer version 7.6 unicode SEH local buffer overflow exploit.

Nsauditor 3.2.1.0 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Nsauditor version 3.2.1.0 SEH buffer overflow exploit with ASLR bypass.

Xinfire TV Player 6.0.1.2 Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in Xinfire TV Player Pro and Standard version 6.0.1.2. When the application is used to import a specially crafted plf file, a buffer overflow occurs allowing arbitrary code execution. Tested successfully on Win7, Win10. This software is similar as Aviosoft Digital TV Player and BlazeVideo HDTV Player.

Xinfire DVD Player 5.5.0.0 Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in Xinfire DVD Player Pro and Standard version 5.5.0.0. When the application is used to import a specially crafted plf file, a buffer overflow occurs allowing arbitrary code execution. Tested successfully on Win7, Win10. This software is similar as DVD X Player and BlazeDVD.

Centreon 19.10.5 SQL Injection

Posted by deepcore under exploit (No Respond)

Centreon version 19.10.5 suffers from a remote SQL injection vulnerability.

Sky File v2.1.0 iOS – Multiple Web Vulnerabilities

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered multiple web vulnerabilities in the official Sky File v2.1.0 …

Mahara v19.10.2 CMS – Persistent Cross Site Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered a persistent cross site vulnerability in the Mahara v19.10.2 …

[webapps] PMB 5.6 – 'logid' SQL Injection

Posted by deepcore under Security (No Respond)

PMB 5.6 – ‘logid’ SQL Injection

Tags: ,

[webapps] CSZ CMS 1.2.7 – Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

CSZ CMS 1.2.7 – Persistent Cross-Site Scripting

Tags: ,