Subscribe via feed.
Archive for July, 2020

BIG-IP TMUI Remote Code Execution

Posted by deepcore under exploit (No Respond)

This exploit demonstrates the remote code execution vulnerability in the Traffic Management User Interface (TMUI) in BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1 through 11.6.5.1.

Sony PS4 / FreeBSD ip6_setpktopt Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Sony PS4 versions prior to 7.02 and FreeBSD versions 9 and 12 ip6_setpktopt kernel local privilege escalation proof of concept exploit.

Online Shopping Portal 3.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Shopping Portal version 3.1 suffers from a remote SQL injection vulnerability.

CDATA OLTs Backdoor / Privilege Escalation / Information Disclosure

Posted by deepcore under exploit (No Respond)

Various CDATA OLTs suffer from backdoor access with telnet, credential leaks, shell escape with root privileges, denial of service, and weak encryption algorithm vulnerabilities.

F5 BIG-IP TMUI Directory Traversal / File Upload / Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a directory traversal in F5’s BIG-IP Traffic Management User Interface (TMUI) to upload a shell script and execute it as the root user.

ClearPass Policy Manager Unauthenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for ClearPass Policy Manager which suffers from an unauthenticated remote command execution vulnerability.

http://mlds.go.th/z.htm

Posted by deepcore under defacement (No Respond)

http://mlds.go.th/z.htm notified by Mr.L3RB1

Tags:

[webapps] BSA Radar 1.6.7234.24750 – Cross-Site Request Forgery (Change Password)

Posted by deepcore under Security (No Respond)

BSA Radar 1.6.7234.24750 – Cross-Site Request Forgery (Change Password)

Tags: ,

[webapps] SuperMicro IPMI 03.40 – Cross-Site Request Forgery (Add Admin)

Posted by deepcore under Security (No Respond)

SuperMicro IPMI 03.40 – Cross-Site Request Forgery (Add Admin)

Tags: ,

File Management System 1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

File Management System version 1.1 suffers from a persistent cross site scripting vulnerability.