Subscribe via feed.
Archive for May, 2020

Pi-Hole heisenbergCompensator Blocklist OS Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command execution in Pi-Hole versions 4.4 and below. A new blocklist is added, and then an update is forced (gravity) to pull in the blocklist content. PHP content is then written to a file within the webroot. Phase 1 writes a sudo pihole command to launch teleporter, effectively running a […]

Dolibarr 11.0.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Dolibarr version 11.0.3 suffers from a cross site scripting vulnerability.

Victor CMS 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Victor CMS version 1.0 suffers from a persistent cross site scripting vulnerability.

Victor CMS 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Victor CMS version 1.0 suffers from a remote SQL injection vulnerability.

qdPM 9.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

qdPM version 9.1 suffers from a persistent cross site scripting vulnerability.

Submitty 20.04.01 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Submitty version 20.04.01 suffers from a persistent cross site scripting vulnerability.

NukeViet VMS 4.4.00 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

NukeViet VMS version 4.4.00 suffers from a cross site request forgery vulnerability.

PHP-Fusion 9.03.50 SQL Injection

Posted by deepcore under exploit (No Respond)

PHP-Fusion version 9.03.50 suffers from a remote SQL injection vulnerability.

Victor CMS 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Victor CMS version 1.0 suffers from an authenticated remote shell upload vulnerability.

[remote] Pi-Hole – heisenbergCompensator Blocklist OS Command Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Pi-Hole – heisenbergCompensator Blocklist OS Command Execution (Metasploit)

Tags: ,