Subscribe via feed.
Archive for August, 2020

Gantt-Chart For Jira 5.5.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Gantt-Chart for Jira versions 5.5.4 and below suffer from a cross site scripting vulnerability.

Documalis Free PDF Editor 5.7.2.26 / Documalis Free PDF Scanner 5.7.2.122 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the Documalis Free PDF Editor or Documalis […]

[webapps] Stock Management System 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Stock Management System 1.0 – Authentication Bypass

Tags: ,

[dos] QlikView 12.50.20000.0 – 'FTP Server Address' Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

QlikView 12.50.20000.0 – ‘FTP Server Address’ Denial of Service (PoC)

Tags: ,

[dos] ACTi NVR3 Standard or Professional Server 3.0.12.42 – Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

ACTi NVR3 Standard or Professional Server 3.0.12.42 – Denial of Service (PoC)

Tags: ,

Online Bike Rental 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Online Bike Rental version 1.0 suffers from an authenticated remote shell upload vulnerability.

All-Dynamics Software enlogic:show Digital Signage System 2.0.2 CSRF

Posted by deepcore under exploit (No Respond)

All-Dynamics Software enlogic:show Digital Signage System version 2.0.2 suffers from a cross site request forgery vulnerability.

All-Dynamics Software enlogic:show Digital Signage System 2.0.2 Session Fixation

Posted by deepcore under exploit (No Respond)

All-Dynamics Software enlogic:show Digital Signage System version 2.0.2 suffers from a session fixation vulnerability.

CloudMe 1.11.2 SEH Buffer Overflow

Posted by deepcore under exploit (No Respond)

CloudMe version 1.11.2 SEH buffer overflow exploit.

BacklinkSpeed 2.4 Buffer Overflow

Posted by deepcore under exploit (No Respond)

BacklinkSpeed version 2.4 SEH buffer overflow proof of concept exploit.