Subscribe via feed.
Archive for August, 2020

GetSimple CMS Multi User 1.8.2 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

GetSimple CMS Multi User plugin version 1.8.2 suffers from multiple cross site request forgery vulnerabilities.

Microsoft Windows AppContainer Enterprise Authentication Capability Bypass

Posted by deepcore under exploit (No Respond)

On Microsoft Windows 10 1909, LSASS does not correctly enforce the Enterprise Authentication Capability which allows any AppContainer to perform network authentication with the user’s credentials.

vBulletin 5.x Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a logic bug within the template rendering code in vBulletin 5.x. The module uses the vBulletin template rendering functionality to render the widget_tabbedcontainer_tab_panel template while also providing the widget_php argument. This causes the former template to load the latter bypassing filters originally put in place to address CVE-2019-16759. This also allows […]

Fuel CMS 1.4.7 SQL Injection

Posted by deepcore under exploit (No Respond)

Fuel CMS version 1.4.7 suffers from an authenticated remote SQL injection vulnerability.

SugarCRM Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SugarCRM versions prior to 10.1.10 suffer from multiple cross site scripting vulnerabilities.

SugarCRM SQL Injection

Posted by deepcore under exploit (No Respond)

SugarCRM versions prior to 10.1.10 suffer from a remote SQL injection vulnerability.

Avian JVM 1.2.0 Integer Overflow

Posted by deepcore under exploit (No Respond)

Avian JVM version 1.2.0 suffers from multiple vm::arrayCopy() integer overflow vulnerabilities.

Avian JVM 1.2.0 Silent Return

Posted by deepcore under exploit (No Respond)

Avian JVM version 1.2.0 suffers from a silent return issue in the vm::arrayCopy method defined in classpath-common.h, where multiple boundary checks are performed to prevent out-of-bounds memory read/write. One of these boundary checks makes the code return silently when a negative length is provided instead of throwing an exception.

[webapps] GetSimple CMS Plugin Multi User 1.8.2 – Cross-Site Request Forgery (Add Admin)

Posted by deepcore under Security (No Respond)

GetSimple CMS Plugin Multi User 1.8.2 – Cross-Site Request Forgery (Add Admin)

Tags: ,

[webapps] Artica Proxy 4.3.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Artica Proxy 4.3.0 – Authentication Bypass

Tags: ,