Subscribe via feed.
Archive for September, 2020

[webapps] Cabot 0.11.12 – Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

Cabot 0.11.12 – Persistent Cross-Site Scripting

Tags: ,

https://www.pattawee.go.th/U72.html

Posted by deepcore under defacement (No Respond)

https://www.pattawee.go.th/U72.html notified by Unravel72

Tags:

http://www.roiet.go.th

Posted by deepcore under defacement (No Respond)

http://www.roiet.go.th notified by TAHU PETIS

Tags:

COVR 3902 1.01B0 Hardcoded Credentials

Posted by deepcore under exploit (No Respond)

The COVR 3902 REVA router with firmware 1.01B0 has hardcoded telnet credentials.

Hyland OnBase SQL Injection

Posted by deepcore under exploit (No Respond)

All versions up to and prior to OnBase Foundation EP1 (tested: 19.8.9.1000) and OnBase 18 (tested: 18.0.0.32) suffer from a multitude of remote SQL injection vulnerabilities.

Nord VPN 6.31.13.0 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Nord VPN version 6.31.13.0 suffers from an unquoted service path vulnerability.

SiteMagic CMS 4.4.2 Shell Upload

Posted by deepcore under exploit (No Respond)

SiteMagic CMS version 4.4.2 suffers from a remote shell upload vulnerability.

Noise-Java AESGCMFallbackCipherState.encryptWithAd() Insufficient Boundary Checks

Posted by deepcore under exploit (No Respond)

Noise-Java suffers from an issue located in the AESGCMFallbackCipherState.encryptWithAd() method defined in AESGCMFallbackCipherState.java, where multiple boundary checks are performed to prevent invalid length or offsets from being specified for the encrypt or copy operation. However, some checks were found to be either incomplete or missing.

Noise-Java ChaChaPolyCipherState.encryptWithAd() Insufficient Boundary Checks

Posted by deepcore under exploit (No Respond)

Noise-Java suffers from an issue located in the ChaChaPolyCipherState.encryptWithAd() method defined in ChaChaPolyCipherState.java, where multiple boundary checks are performed to prevent invalid length or offsets from being specified for the encrypt or copy operation. However, some checks were found to be either incomplete or missing.

Red Lion N-Tron 702-W / 702M12-W 2.0.26 XSS / CSRF / Shell

Posted by deepcore under exploit (No Respond)

Red Lion N-Tron 702-W and 702M12-W versions 2.0.26 and below suffer from cross site request forgery, hidden shell interface, cross site scripting and busybox vulnerabilities.