Subscribe via feed.
Archive for September, 2020

Noise-Java AESGCMOnCtrCipherState.encryptWithAd() Insufficient Boundary Checks

Posted by deepcore under exploit (No Respond)

Noise-Java suffers from an issue located in the AESGCMOnCtrCipherState.encryptWithAd() method defined in AESGCMOnCtrCipherState.java, where multiple boundary checks are performed to prevent invalid length or offsets from being specified for the encrypt or copy operation. However, some checks were found to be either incomplete or missing.

Pulse Secure Windows Client Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Windows client for Pulse Secure versions prior to 9.1.6 have a TOCTOU bug that allows an attacker to escalate the privilege to NT_AUTHORITYSYSTEM.

ManageEngine Applications Manager Authenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

ManageEngine Applications Manager authenticated remote code execution exploit that leverages the newInstance() and loadClass() methods being used by the “WeblogicReference”, when attempting a Credential Test for a new Monitor. Versions below 14720 are affected.

http://www.1tambon1school.go.th/data/-.txt

Posted by deepcore under defacement (No Respond)

http://www.1tambon1school.go.th/data/-.txt notified by /Rayzky_

Tags:

[local] Nord VPN-6.31.13.0 – 'nordvpn-service' Unquoted Service Path

Posted by deepcore under Security (No Respond)

Nord VPN-6.31.13.0 – ‘nordvpn-service’ Unquoted Service Path

Tags: ,

Go CGI / FastCGI Transport Cross Site Scripting

Posted by deepcore under exploit (No Respond)

The CGI and FastCGI implementations in the Go standard library behave differently from the HTTP server implementation when serving content. In contrast to the documented behavior, they may return non-HTML data as HTML. This may lead to cross site scripting vulnerabilities even if uploaded data has been validated during upload. Versions 1.15 and 1.14.7 and […]

[local] BarracudaDrive v6.5 – Insecure Folder Permissions

Posted by deepcore under Security (No Respond)

BarracudaDrive v6.5 – Insecure Folder Permissions

Tags: ,

[webapps] SiteMagic CMS 4.4.2 – Arbitrary File Upload (Authenticated)

Posted by deepcore under Security (No Respond)

SiteMagic CMS 4.4.2 – Arbitrary File Upload (Authenticated)

Tags: ,

[webapps] Daily Tracker System 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Daily Tracker System 1.0 – Authentication Bypass

Tags: ,

[webapps] BloodX CMS 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

BloodX CMS 1.0 – Authentication Bypass

Tags: ,