Subscribe via feed.
Archive for April, 2020

[remote] ThinkPHP – Multiple PHP Injection RCEs (Metasploit)

Posted by deepcore under Security (No Respond)

ThinkPHP – Multiple PHP Injection RCEs (Metasploit)

Tags: ,

[remote] TP-Link Archer A7/C7 – Unauthenticated LAN Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

TP-Link Archer A7/C7 – Unauthenticated LAN Remote Code Execution (Metasploit)

Tags: ,

[local] VMware Fusion – USB Arbitrator Setuid Privilege Escalation (Metasploit)

Posted by deepcore under Security (No Respond)

VMware Fusion – USB Arbitrator Setuid Privilege Escalation (Metasploit)

Tags: ,

Free Desktop Clock 3.0 Stack Overflow

Posted by deepcore under exploit (No Respond)

Free Desktop Clock version 3.0 unicode SEH stack overflow exploit.

Subex ROC Partner Settlement 10.5 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Subex ROC Partner Settlement version 10.5 suffers from an insecure direct object reference vulnerability in the change password function that can allow for account takeover.

Webtateas 2.0 Arbitrary File Read

Posted by deepcore under exploit (No Respond)

Webtateas version 2.0 suffers from an arbitrary file read vulnerability.

Huawei HG630 2 Router Authentication Bypass

Posted by deepcore under exploit (No Respond)

Huawei HG630 2 Router suffers from an authentication bypass vulnerability.

WSO2 API Manager Carbon Interface 3.0.0 File Delete

Posted by deepcore under exploit (No Respond)

WSO2 API Manager Carbon interface version 3.0.0 suffers from an arbitrary file deletion vulnerability.

WordPress Media Library Assistant 2.81 Local File Inclusion

Posted by deepcore under exploit (No Respond)

WordPress Media Library Assistant plugin version 2.81 suffers from a local file inclusion vulnerability.

B64dec 1.1.2 Buffer Overflow

Posted by deepcore under exploit (No Respond)

B64dec version 1.1.2 SEH buffer overflow exploit with egg hunter.