Subscribe via feed.
Archive for July, 2020

FTPDummy! 4.80 Local Buffer Overflow

Posted by deepcore under exploit (No Respond)

FTPDummy! version 4.80 local SEH buffer overflow exploit that pops calc.exe.

EternalBlueC EternalBlue Suite

Posted by deepcore under exploit (No Respond)

EternalBlueC is the EternalBlue suite remade in C which includes an MS17-010 exploit, EternalBlue/MS17-010 vulnerability detector, DoublePulsar detector, and DoublePulsar UploadDLL and shellcode.

Sophos VPN Web Panel 2020 Denial Of Service

Posted by deepcore under exploit (No Respond)

Sophos VPN Web Panel 2020 denial of service proof of concept exploit.

WordPress NexosReal Estate Theme 1.7 Cross Site Scripting / SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress NexosReal Estate Theme version 1.7 suffers from cross site scripting and remote SQL injection vulnerabilities.

Docsify.js 4.11.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Docsify.js version 4.11.4 suffers from a cross site scripting vulnerability.

ZenTao Pro 8.8.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in ZenTao Pro 8.8.2 and earlier versions in order to execute arbitrary commands with SYSTEM privileges. Valid credentials for a ZenTao admin account are required. This module has been successfully tested against ZenTao 8.8.1 and 8.8.2 running on Windows 10 (XAMPP server).

[local] Snes9K 0.09z – 'Port Number' Buffer Overflow (SEH)

Posted by deepcore under Security (No Respond)

Snes9K 0.09z – ‘Port Number’ Buffer Overflow (SEH)

Tags: ,

[local] FTPDummy 4.80 – Local Buffer Overflow (SEH)

Posted by deepcore under Security (No Respond)

FTPDummy 4.80 – Local Buffer Overflow (SEH)

Tags: ,

[webapps] UBICOD Medivision Digital Signage 1.5.1 – Authorization Bypass

Posted by deepcore under Security (No Respond)

UBICOD Medivision Digital Signage 1.5.1 – Authorization Bypass

Tags: ,

LibreHealth 2.0.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

LibreHealth version 2.0.0 authentication remote code execution exploit that leverages file upload.