Subscribe via feed.
Archive for June, 2020

[webapps] SmarterMail 16 – Arbitrary File Upload

Posted by deepcore under Security (No Respond)

SmarterMail 16 – Arbitrary File Upload

Tags: ,

Sistem Informasi Pengumuman Kelulusan Online 1.0 CSRF

Posted by deepcore under exploit (No Respond)

Sistem Informasi Pengumuman Kelulusan Online version 1.0 suffers from a cross site request forgery vulnerability.

LinuxKI Toolset 6.01 Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in LinuxKI Toolset versions 6.01 and below which allows remote code execution. The kivis.php pid parameter received from the user is sent to the shell_exec function, resulting in the security vulnerability.

Microsoft Windows Privilege Escalation / Code Execution

Posted by deepcore under exploit (No Respond)

This research discusses two different vulnerabilities addressed in the June 2020 Microsoft Patch Tuesday. An integer overflow in OLE marshalling and a race condition with arbitrary file deletion are described in detail.

[local] Frigate Professional 3.36.0.9 – 'Find Computer' Local Buffer Overflow (SEH) (PoC)

Posted by deepcore under Security (No Respond)

Frigate Professional 3.36.0.9 – ‘Find Computer’ Local Buffer Overflow (SEH) (PoC)

Tags: ,

Virtual Airlines Manager 2.6.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Virtual Airlines Manager version 2.6.2 suffers from a remote SQL injection vulnerability.

Bludit 3.9.12 Directory Traversal

Posted by deepcore under exploit (No Respond)

Bludit version 3.9.12 suffers from a directory traversal vulnerability.

Bandwidth Monitor 3.9 Full ROP Buffer Overflow

Posted by deepcore under exploit (No Respond)

Bandwidth Monitor version 3.9 full ROP buffer overflow exploit with SEH, DEP, and ASLR taken into consideration.

WebUntis 2020.12.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WebUntis versions 2020.12.1 and below suffer from a persistent cross site scripting vulnerability.

Joomla J2 Store 3.3.11 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla J2 Store version 3.3.11 suffers from an authenticated remote SQL injection vulnerability.