Subscribe via feed.
Archive for May, 2020

BlogEngine 3.3 XML Injection

Posted by deepcore under exploit (No Respond)

BlogEngine version 3.3 suffers from an XML external entity injection vulnerability.

osTicket 1.14.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

osTicket version 1.14.1 suffers from a persistent cross site scripting vulnerability.

Fishing Reservation System SQL Injection

Posted by deepcore under exploit (No Respond)

Fishing Reservation System suffers from multiple remote SQL injection vulnerabilities.

BoltWire 6.03 Local File Inclusion

Posted by deepcore under exploit (No Respond)

BoltWire version 6.03 suffers from a local file inclusion vulnerability.

HP Performance Monitoring xglance Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module is an exploit that takes advantage of xglance-bin, part of HP’s Glance (or Performance Monitoring) version 11 and subsequent, which was compiled with an insecure RPATH option. The RPATH includes a relative path to -L/lib64/ which can be controlled by a user. Creating libraries in this location will result in an escalation […]

Veeam ONE Agent .NET Deserialization

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a .NET deserialization vulnerability in the Veeam ONE Agent before the hotfix versions 9.5.5.4587 and 10.0.1.750 in the 9 and 10 release lines. Specifically, the module targets the HandshakeResult() method used by the Agent. By inducing a failure in the handshake, the Agent will deserialize untrusted data. Tested against the pre-patched […]

Outline Service 1.3.3 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Outline Service version 1.3.3 suffers from an unquoted service path vulnerability.

Frigate 3.36 SEH Buffer Overflow

Posted by deepcore under exploit (No Respond)

Frigate version 3.36 SEH buffer overflow exploit that pops a calculator.

addressbook 9.0.0.1 SQL Injection

Posted by deepcore under exploit (No Respond)

addressbook version 9.0.0.1 suffers from a remote SQL injection vulnerability.

File Explorer 1.4 Access Bypass

Posted by deepcore under exploit (No Respond)

File Explorer for iOS version 1.4 suffers from an access bypass vulnerability.