Subscribe via feed.
Archive for April, 2020

Oracle Solaris 11.x / 10 whodo / w Buffer Overflow

Posted by deepcore under exploit (No Respond)

A difficult to exploit heap-based buffer overflow in setuid root whodo and w binaries distributed with Solaris allows local users to corrupt memory and potentially execute arbitrary code in order to escalate privileges.

http://www.rb2.go.th/admin/pic_title/1700400107041202004171587057757.jpg

Posted by deepcore under defacement (No Respond)

http://www.rb2.go.th/admin/pic_title/1700400107041202004171587057757.jpg notified by Mr.Kro0oz.305

Tags:

Swift File Transfer Mobile – Multiple Web Vulnerabilities

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered multiple web vulnerabilities in the official Swift File Trans…

Fork CMS v5.8.0 – Multiple Persistent Web Vulnerbilities

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered multiple persistent web vulnerabilities in the official Fork …

Nexus Repository Manager 3.21.1-01 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a Java Expression Language (EL) injection in Nexus Repository Manager versions up to and including 3.21.1 to execute code as the Nexus user. Tested against 3.21.1-01.

Microsoft Windows Unquoted Service Path Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a logic flaw due to how the lpApplicationName parameter is handled. When the lpApplicationName contains a space, the file name is ambiguous. Take this file path as example: C:program fileshello.exe; The Windows API will try to interpret this as two possible paths: C:program.exe, and C:program fileshello.exe, and then execute all of […]

[local] Code Blocks 16.01 – Buffer Overflow (SEH) UNICODE

Posted by deepcore under Security (No Respond)

Code Blocks 16.01 – Buffer Overflow (SEH) UNICODE

Tags: ,

[remote] Nexus Repository Manager – Java EL Injection RCE (Metasploit)

Posted by deepcore under Security (No Respond)

Nexus Repository Manager – Java EL Injection RCE (Metasploit)

Tags: ,

Pinger 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Pinger version 1.0 suffers from a remote code execution vulnerability.

BlazeDVD 7.0.2 Buffer Overflow

Posted by deepcore under exploit (No Respond)

BlazeDVD version 7.0.2 SEH buffer overflow exploit.