Subscribe via feed.
Archive for June, 2020

[local] IObit Uninstaller 9.5.0.15 – 'IObit Uninstaller Service' Unquoted Service Path

Posted by deepcore under Security (No Respond)

IObit Uninstaller 9.5.0.15 – ‘IObit Uninstaller Service’ Unquoted Service Path

Tags: ,

[webapps] Clinic Management System 1.0 – Unauthenticated Remote Code Execution

Posted by deepcore under Security (No Respond)

Clinic Management System 1.0 – Unauthenticated Remote Code Execution

Tags: ,

[webapps] Hostel Management System 2.0 – 'id' SQL Injection (Unauthenticated)

Posted by deepcore under Security (No Respond)

Hostel Management System 2.0 – ‘id’ SQL Injection (Unauthenticated)

Tags: ,

[webapps] AirControl 1.4.2 – PreAuth Remote Code Execution

Posted by deepcore under Security (No Respond)

AirControl 1.4.2 – PreAuth Remote Code Execution

Tags: ,

VMware vCenter Server 6.7 Authentication Bypass

Posted by deepcore under exploit (No Respond)

VMware vCenter Server version 6.7 authentication bypass exploit.

QuickBox Pro 2.1.8 Remote Code Execution

Posted by deepcore under exploit (No Respond)

QuickBox Pro versions 2.1.8 and below suffer from an authenticated remote code execution vulnerability.

Microsoft Windows SMBGhost Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Windows SMBGhost pre-authentication remote code execution exploit.

vBulletin 5.6.1 SQL Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a SQL injection vulnerability found in vBulletin versions 5.6.1 and below. This module uses the getIndexableContent vulnerability to reset the administrator’s password and it then uses the administrators login information to achieve remote code execution on the target. This module has been tested successfully on vBulletin version 5.6.1 on the Ubuntu […]

WordPress BBPress 2.5 Privilege Escalation

Posted by deepcore under exploit (No Respond)

WordPress BBPress plugin version 2.5 suffers from an unauthenticated privilege escalation vulnerability.

We-Com Municipality Portal CMS 2.1.x Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

We-Com Municipality Portal CMS version 2.1.x suffers from cross site scripting and remote SQL injection vulnerabilities.