Subscribe via feed.
Archive for May, 2020

WebLogic Server Deserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a Java object deserialization vulnerability in multiple versions of WebLogic. Unauthenticated remote code execution can be achieved by sending a serialized BadAttributeValueExpException object over the T3 protocol to vulnerable WebLogic servers.

Gym Management System 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Gym Management System version 1.0 suffers from an unauthenticated remote code execution vulnerability.

Qualys Security Advisory – Qmail Remote Code Execution

Posted by deepcore under exploit (No Respond)

In 2005, three vulnerabilities were discovered in qmail but were never fixed because they were believed to be unexploitable in a default installation. Qualys recently re-discovered these vulnerabilities and were able to exploit one of them remotely in a default installation.

VUPlayer 2.49 .m3u Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

VUPlayer version 2.49 .m3u local buffer overflow exploit with DEP and ASLR.

Druva inSync Windows Client 6.6.3 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Druva inSync Windows Client version 6.6.3 suffers from a local privilege escalation vulnerability.

Synology DiskStation Manager smart.cgi Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability found in Synology DiskStation Manager (DSM) versions prior to 5.2-5967-5, which allows the execution of arbitrary commands under root privileges after website authentication. The vulnerability is located in webman/modules/StorageManager/smart.cgi, which allows appending of a command to the device to be scanned. However, the command with drive is limited to […]

Plesk / myLittleAdmin ViewState .NET Deserialization

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a ViewState .NET deserialization vulnerability in web-based MS SQL Server management tool myLittleAdmin, for version 3.8 and likely older versions, due to hardcoded machineKey parameters in the web.config file for ASP.NET. Popular web hosting control panel Plesk offers myLittleAdmin as an optional component that is selected automatically during “full” installation. This […]

Apple Security Advisory 2020-05-20-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2020-05-20-1 – Xcode 11.5 is now available and addresses an issue where a crafted git URL that contains a newline in it may cause credential information to be provided for the wrong host.

Tags: , ,

http://charoenrat.go.th

Posted by deepcore under defacement (No Respond)

http://charoenrat.go.th notified by 1K4lL_*

Tags:

[webapps] Online Discussion Forum Site 1.0 – Remote Code Execution

Posted by deepcore under Security (No Respond)

Online Discussion Forum Site 1.0 – Remote Code Execution

Tags: ,