Subscribe via feed.
Archive for June, 2020

Online Course Registration 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Course Registration version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Castel NextGen DVR 1.0.0 Bypass / CSRF / Disclosure

Posted by deepcore under exploit (No Respond)

Castel NextGen DVR version 1.0.0 suffers from authorization bypass, credential disclosure, and cross site request forgery vulnerabilities.

Cisco UCS Director Cloupia Script Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authentication bypass and directory traversals in Cisco UCS Director versions prior to 6.7.4.0 to leak the administrator’s REST API key and execute a Cloupia script containing an arbitrary root command. Note that the primary functionality of this module is to leverage the Cloupia script interpreter to execute code. This functionality […]

Avaya IP Office 11 Insecure Transit / Password Disclosure

Posted by deepcore under exploit (No Respond)

Avaya IP Office versions 9.1.8.0 through 11 suffer from an insecure transit vulnerability that allows for password disclosure.

WinGate 9.4.1.5998 Insecure Permissions / Privilege Escalation

Posted by deepcore under exploit (No Respond)

WinGate version 9.4.1.5998 suffers from an insecure permissions vulnerability that allows for privilege escalation.

http://www.lerdsin.go.th

Posted by deepcore under defacement (No Respond)

http://www.lerdsin.go.th notified by saeed0511

Tags:

AirControl 1.4.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

AirControl version 1.4.2 suffers from a pre-authentication remote code execution vulnerability.

IObit Uninstaller 9.5.0.15 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

IObit Uninstaller version 9.5.0.15 suffers from an IObit Uninstaller Service unquoted service path vulnerability.

Clinic Management System 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Clinic Management System version 1.0 suffers from an unauthenticated remote code execution vulnerability.

Navigate CMS 2.8.7 SQL Injection

Posted by deepcore under exploit (No Respond)

Navigate CMS version 2.8.7 suffers from an authenticated remote SQL injection vulnerability.