Subscribe via feed.
Archive for May, 2020

[local] VUPlayer 2.49 .m3u – Local Buffer Overflow (DEP,ASLR)

Posted by deepcore under Security (No Respond)

VUPlayer 2.49 .m3u – Local Buffer Overflow (DEP,ASLR)

Tags: ,

Craft CMS 3 vCard 1.0.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Craft CMS 3 with vCard plugin version 1.0.0 suffers from a remote code execution vulnerability.

CloudMe 1.11.2 SEH / DEP / ASLR Buffer Overflow

Posted by deepcore under exploit (No Respond)

CloudMe version 1.11.2 SEH / DEP / ASLR buffer overflow exploit.

http://ecocenter.diw.go.th/87.html

Posted by deepcore under defacement (No Respond)

http://ecocenter.diw.go.th/87.html notified by Family Attack Cyber

Tags:

[webapps] forma.lms 5.6.40 – Cross-Site Request Forgery (Change Admin Email)

Posted by deepcore under Security (No Respond)

forma.lms 5.6.40 – Cross-Site Request Forgery (Change Admin Email)

Tags: ,

[dos] AbsoluteTelnet 11.21 – 'Username' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

AbsoluteTelnet 11.21 – ‘Username’ Denial of Service (PoC)

Tags: ,

Open-Xchange Dovecot 2.3.10 Null Pointer Dereference / Denial Of Service

Posted by deepcore under exploit (No Respond)

Open-Xchange Dovecot versions 2.3.0 through 2.3.10 suffer from null pointer dereference and denial of service vulnerabilities.

Protection Licensing Toolkit ReadyAPI 3.2.5 Code Execution / Deserialization

Posted by deepcore under exploit (No Respond)

Protection Licensing Toolkit ReadyAPI version 3.2.5 suffers from an unsafe deserialization vulnerability that allows for remote code execution.

[webapps] CraftCMS 3 vCard Plugin 1.0.0 – Remote Code Execution

Posted by deepcore under Security (No Respond)

CraftCMS 3 vCard Plugin 1.0.0 – Remote Code Execution

Tags: ,

Mikrotik Router Monitoring System 1.2.3 SQL Injection

Posted by deepcore under exploit (No Respond)

Mikrotik Router Monitoring System versions 1.2.3 and below suffer from a remote SQL injection vulnerability.