Subscribe via feed.
Archive for May, 2020

[webapps] i-doit Open Source CMDB 1.14.1 – Arbitrary File Deletion

Posted by deepcore under Security (No Respond)

i-doit Open Source CMDB 1.14.1 – Arbitrary File Deletion

Tags: ,

[webapps] YesWiki cercopitheque 2020.04.18.1 – 'id' SQL Injection

Posted by deepcore under Security (No Respond)

YesWiki cercopitheque 2020.04.18.1 – ‘id’ SQL Injection

Tags: ,

[webapps] Online Clothing Store 1.0 – Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

Online Clothing Store 1.0 – Persistent Cross-Site Scripting

Tags: ,

xt:Commerce 5.4.1 / 6.2.1 / 6.2.2 Improper Access Control

Posted by deepcore under exploit (No Respond)

xt:Commerce version 5.4.1, 6.2.1, and 6.2.2 suffer from an improper access control vulnerability. A logged-in customer can create and alter addresses. These addresses are referenced by incrementing IDs. On saving an address, an attacker could change the ID of the address to write the data to. If the ID belongs to an address which does […]

OpenSSL signature_algorithms_cert Denial Of Service

Posted by deepcore under exploit (No Respond)

Proof of concept denial of service exploit for the recent OpenSSL signature_algorithms_cert vulnerability.

TP-LINK Cloud Cameras NCXXX Bonjour Command Injection

Posted by deepcore under exploit (No Respond)

TP-LINK Cloud Cameras including products NC200, NC210, NC220, NC230, NC250, NC260, and NC450 suffer from a command injection vulnerability. The issue is located in the swSystemSetProductAliasCheck method of the ipcamera binary (Called when setting a new alias for the device via /setsysname.fcgi), where despite a check on the name length, no other checks are in […]

TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key

Posted by deepcore under exploit (No Respond)

TP-LINK Cloud Cameras including products NC200, NC210, NC220, NC230, NC250, NC260, and NC450 suffer from having a hardcoded encryption key. The issue is located in the methods swSystemBackup and sym.swSystemRestoreFile, where a hardcoded encryption key is used in order to encrypt/decrypt a config backup file. The algorithm in use is DES ECB with modified s-boxes […]

TP-LINK Cloud Cameras NCXXX SetEncryptKey Command Injection

Posted by deepcore under exploit (No Respond)

TP-LINK Cloud Cameras including products NC260 and NC450 suffer from a command injection vulnerability. The issue is located in the httpSetEncryptKeyRpm method (handler for /setEncryptKey.fcgi) of the ipcamera binary, where the user-controlled EncryptKey parameter is used directly as part of a command line to be executed as root without any input sanitization.

FlashGet 1.9.6 Buffer Overflow Proof Of Concept

Posted by deepcore under exploit (No Respond)

FlashGet version 1.9.6 remote buffer overflow proof of concept exploit.

iJoomla AdAgency 6.0.9 SQL Injection

Posted by deepcore under exploit (No Respond)

iJoomla AdAgency component version 6.0.9 suffers from a remote SQL injection vulnerability.