Subscribe via feed.
Archive for May, 2020

ACal 2.2.6 Remote Code Execution

Posted by deepcore under exploit (No Respond)

ACal version 2.2.6 suffers from a one-click remote code execution vulnerability.

Microsoft Windows Task Scheduler Security Feature Bypass

Posted by deepcore under exploit (No Respond)

Compass Security identified a security feature bypass vulnerability in Microsoft Windows. Due to the absence of integrity verification requirements for the RPC protocol and in particular the Task Scheduler, a man-in-the-middle attacker can relay his victim’s NTLM authentication to a target of his choice over the RPC protocol. Provided the victim has administrative privileges on […]

ManageEngine AssetExplorer Authenticated Command Execution

Posted by deepcore under exploit (No Respond)

ManageEngine AssetExplorer versions prior to 6.5 (6503) suffer from an authenticated remote command execution vulnerability.

http://odpc1.ddc.moph.go.th/LPHJ/public/site/images/zbi/Ma.gif

Posted by deepcore under defacement (No Respond)

http://odpc1.ddc.moph.go.th/LPHJ/public/site/images/zbi/Ma.gif notified by Moroccan Revolution

Tags:

Subrion CMS 4.2.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Subrion CMS version 4.2.1 suffers from a cross site scripting vulnerability.

Subrion CMS 4.2.1 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Subrion CMS version 4.2.1 suffers from a cross site request forgery vulnerability.

Dameware Remote Support 12.1.1.273 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Dameware Remote Support version 12.1.1.273 suffers from a buffer overflow vulnerability.

Netlink XPON 1GE WiFi V2801RGW Remote Command Execution

Posted by deepcore under exploit (No Respond)

Netlink XPON 1GE WiFi V2801RGW suffers from a remote command execution vulnerability. Version 3.3.0-190627 is affected.

E-Commerce System 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

E-Commerce System version 1.0 suffers from a remote code execution vulnerability.

Cellebrite UFED 7.5.0.845 Desktop Escape / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Cellebrite UFED device implements local operating system policies that can be circumvented to obtain a command prompt. From there privilege escalation is possible using public exploits. Versions 5.0 through 7.5.0.845 are affected.