Subscribe via feed.
Archive for June, 2020

OX App Suite / OX Documents 7.10.3 XSS / SSRF / Improper Validation

Posted by deepcore under exploit (No Respond)

OX App Suite and OX Documents versions 7.10.3 and below suffer from server-side request forgery, cross site scripting, improper parameter validation, and XML injection vulnerabilities.

OX Guard 2.10.3 Cross Site Scripting / Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

OX Guard version 2.10.3 suffers from server-side request forgery and cross site scripting vulnerabilities.

SmarterMail 16 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

SmarterMail 16 suffers from an arbitrary file upload vulnerability.

Sysax MultiServer 6.90 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sysax MultiServer version 6.90 suffers from a cross site scripting vulnerability.

PHP-Fusion 9.03.60 PHP Object Injection / SQL Injection

Posted by deepcore under exploit (No Respond)

PHP-Fusion version 9.03.60 PHP object injection to SQL injection pre-authentication exploit.

GOG GalaxyClientService Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module will send arbitrary file_paths to the GOG GalaxyClientService, which will be executed with SYSTEM privileges (verified on GOG Galaxy Client v1.2.62 and v2.0.12; prior versions are also likely affected).

10-Strike Bandwidth Monitor 3.9 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

10-Strike Bandwidth Monitor version 3.9 services Svc10StrikeBandMontitor, Svc10StrikeBMWD, and Svc10StrikeBMAgent suffer from unquoted service path vulnerabilities.

Documalis Free PDF Editor Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability in Documalis Free PDF Editor.

Documalis Free PDF Scanner Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow vulnerability in Documalis Free PDF Scanner.

Neon LMS Shell Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a shell upload vulnerability in Neon LMS versions prior to 4.9.1.