Subscribe via feed.
Archive for May, 2020

WordPress Dosimple Theme 2.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Dosimple theme version 2.0 suffers from a cross site scripting vulnerability.

Creative Zone SQL Injection

Posted by deepcore under exploit (No Respond)

Creative Zone suffers from a remote SQL injection vulnerability.

ManageEngine Asset Explorer Windows Agent Remote Code Execution

Posted by deepcore under exploit (No Respond)

The ManageEngine Asset Explorer windows agent suffers form a remote code execution vulnerability. All versions prior to 1.0.29 are affected.

Service Tracing Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module leverages a trusted file overwrite with a dll hijacking vulnerability to gain SYSTEM-level access on vulnerable Windows 10 x64 targets.

Microsoft Windows NtUserMNDragOver Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a NULL pointer dereference vulnerability in MNGetpItemFromIndex(), which is reachable via a NtUserMNDragOver() system call. The NULL pointer dereference occurs because the xxxMNFindWindowFromPoint() function does not effectively check the validity of the tagPOPUPMENU objects it processes before passing them on to MNGetpItemFromIndex(), where the NULL pointer dereference will occur. This module […]

Samsung Android Remote Code Execution

Posted by deepcore under exploit (No Respond)

Samsung Android suffers from multiple interaction-less remote code execution vulnerabilities as well as other remote access issues in the Qmage image codec built into Skia.

Linux futex+VFS Use-After-Free

Posted by deepcore under exploit (No Respond)

Linux futex+VFS suffers from an improper inode reference in get_futex_key() that causes a use-after-free if the superblock goes away.

Linux 5.6 IORING_OP_MADVISE Race Condition

Posted by deepcore under exploit (No Respond)

Linux 5.6 has an issue with IORING_OP_MADVISE racing with coredumping.

http://e-mining.dpim.go.th/java.html

Posted by deepcore under defacement (No Respond)

http://e-mining.dpim.go.th/java.html notified by Al Catraz

Tags:

http://www.nanual.go.th/m-1.html

Posted by deepcore under defacement (No Respond)

http://www.nanual.go.th/m-1.html notified by moncet

Tags: