Subscribe via feed.
Archive for July, 2020

RiteCMS 2.2.1 Remote Code Execution

Posted by deepcore under exploit (No Respond)

RiteCMS version 2.2.1 suffers from an authenticated remote code execution vulnerability.

WhatsApp android-gif-drawable Double-Free

Posted by deepcore under exploit (No Respond)

Proof of concept exploit that leverages a double-free in the DDGifSlurp function in decoding.c in the android-gif-drawable library in order to achieve remote code execution in WhatsApp.

Grafana 7.0.1 Denial Of Service

Posted by deepcore under exploit (No Respond)

Grafana version 7.0.1 denial of service proof of concept exploit.

Microsoft Windows MSHTA.EXE .HTA File XML Injection

Posted by deepcore under exploit (No Respond)

Microsoft Windows mshta.exe allows processing of XML external entities which can result in local data-theft and or program reconnaissance upon opening specially crafted HTA files.

Nagios XI 5.6.12 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Nagios XI version 5.6.12 remote code execution exploit that leverages export-rrd.php.

Fire Web Server 0.1 Denial Of Service

Posted by deepcore under exploit (No Respond)

Fire Web Server version 0.1 remote denial of service proof of concept exploit.

rauLink Software Domotica Web 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

rauLink Software Domotica Web version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

RSA IG+L Aveksa 7.1.1 Remote Code Execution

Posted by deepcore under exploit (No Respond)

RSA IG+L Aveksa version 7.1.1 suffers from a remote code execution vulnerability due to an authorization bypass issue.

openSIS 7.4 Unauthenticated PHP Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits multiple vulnerabilities in openSIS 7.4 and prior versions which could be abused by unauthenticated attackers to execute arbitrary PHP code with the permissions of the webserver. The exploit chain abuses an incorrect access control issue which allows access to scripts which should require the user to be authenticated, and a local […]

[webapps] Joomla! J2 JOBS 1.3.0 – 'sortby' Authenticated SQL Injection

Posted by deepcore under Security (No Respond)

Joomla! J2 JOBS 1.3.0 – ‘sortby’ Authenticated SQL Injection

Tags: ,