Subscribe via feed.
Archive for April, 2020

Code Blocks 16.01 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Code Blocks version 16.01 suffers from a buffer overflow vulnerability.

TAO Open Source Assessment Platform 3.3.0 RC02 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

TAO Open Source Assessment Platform version 3.3.0 RC02 suffers from multiple cross site scripting vulnerabilities.

SMACom 1.2.0 Insecure Transit / Password Disclosure

Posted by deepcore under exploit (No Respond)

SMACom version 1.2.0 suffers from an insecure transit vulnerability that allows for password disclosure.

Metasploit Libnotify Arbitrary Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a shell command injection vulnerability in the libnotify plugin. This vulnerability affects Metasploit versions 5.0.79 and earlier.

Unraid 6.8.0 Authentication Bypass / Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits two vulnerabilities affecting Unraid 6.8.0. An authentication bypass is used to gain access to the administrative interface, and an insecure use of the extract PHP function can be abused for arbitrary code execution as root.

Prestashop 1.7.6.4 XSS / CSRF / Remote Code Execution

Posted by deepcore under exploit (No Respond)

Prestashop versions 1.7.6.4 and below suffer from code execution, cross site request forgery, and cross site scripting vulnerabilities.

Swift File Transfer Mobile Cross Site Scripting / Information Disclosure

Posted by deepcore under exploit (No Respond)

The Swift File Transfer mobile application for ios, blackberry and android suffers from cross site scripting and information disclosure vulnerabilities.

Fork CMS 5.8.0 Script Insertion

Posted by deepcore under exploit (No Respond)

Fork CMS version 5.8.0 suffers from multiple script insertion vulnerabilities.

Common Desktop Environment 1.6 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

A buffer overflow in the _SanityCheck() function in the Common Desktop Environment version distributed with Oracle Solaris 10 1/13 (Update 11) and earlier allows local users to gain root privileges via a long calendar name or calendar owner passed to sdtcm_convert in a malicious calendar file. The open source version of CDE (based on the […]

Common Desktop Environment 2.3.1 / 1.6 libDtSvc Buffer Overflow

Posted by deepcore under exploit (No Respond)

A difficult to exploit stack-based buffer overflow in the _DtCreateDtDirs() function in the Common Desktop Environment version distributed with Oracle Solaris 10 1/13 (Update 11) and earlier may allow local users to corrupt memory and potentially execute arbitrary code in order to escalate privileges via a long X11 display name. The vulnerable function is located […]