Subscribe via feed.
Archive for April, 2020

WSO2 API Manager Carbon Interface 3.0.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WSO2 API Manager Carbon interface version 3.0.0 suffers from a persistent cross site scripting vulnerability.

TVT NVMS 1000 Directory Traversal

Posted by deepcore under exploit (No Respond)

TVT NVMS 1000 suffers from a directory traversal vulnerability.

Edimax Technology EW-7438RPn-v3 Mini 1.27 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Edimax Technology EW-7438RPn-v3 Mini version 1.27 suffers from a remote code execution vulnerability.

MOVEit Transfer 11.1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

MOVEit Transfer version 11.1.1 suffers from a remote SQL injection vulnerability.

Cellebrite UFED 7.29 Hardcoded ADB Authentication Keys

Posted by deepcore under exploit (No Respond)

Cellebrite UFED versions 5.0 through 7.29 use four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

Oracle WebLogic Server 12.2.1.4.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Oracle WebLogic Server version 12.2.1.4.0 suffers from a remote code execution vulnerability.

ThinkPHP 5.0.23 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits one of two PHP injection vulnerabilities in the ThinkPHP web framework to execute code as the web user. Versions up to and including 5.0.23 are exploitable, though 5.0.23 is vulnerable to a separate vulnerability. The module will automatically attempt to detect the version of the software. Tested against versions 5.0.20 and […]

Vesta Control Panel Authenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authenticated command injection vulnerability in the v-list-user-backups bash script file in Vesta Control Panel to gain remote code execution as the root user.

Matrix42 Workspace Management 9.1.2.2765 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Matrix42 Workspace Management version 9.1.2.2765 suffers from a persistent cross site scripting vulnerability.

SuperBackup v2.0.5 iOS – (VCF) Persistent XSS Vulnerability

Posted by deepcore under exploit (No Respond)

The vulnerability laboratory core research team discovered multiple persistent cross site web vulnerabilities in the off…