Subscribe via feed.
Archive for September, 2020

VyOS restricted-shell Escape / Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits command injection vulnerabilities and an insecure default sudo configuration on VyOS versions 1.0.0 through 1.1.8 to execute arbitrary system commands as root. VyOS features a restricted-shell system shell intended for use by low privilege users with operator privileges. This module exploits a vulnerability in the telnet command to break out of […]

Online Shop Project 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Shop Project version 1.0 suffers from a remote SQL injection vulnerability.

Seat Reservation System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Seat Reservation System version 1.0 suffers from a remote SQL injection vulnerability.

BlackCat CMS 1.3.6 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

BlackCat CMS version 1.3.6 suffers from a cross site request forgery vulnerability.

Mida eFramework 2.9.0 Backdoor Access

Posted by deepcore under exploit (No Respond)

Mida eFramework version 2.9.0 suffers from having a backdoor access vulnerability.

[webapps] Flatpress Add Blog 1.0.3 – Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

Flatpress Add Blog 1.0.3 – Persistent Cross-Site Scripting

Tags: ,

[webapps] Comodo Unified Threat Management Web Console 2.7.0 – Remote Code Execution

Posted by deepcore under Security (No Respond)

Comodo Unified Threat Management Web Console 2.7.0 – Remote Code Execution

Tags: ,

[webapps] B-swiss 3 Digital Signage System 3.6.5 – Remote Code Execution

Posted by deepcore under Security (No Respond)

B-swiss 3 Digital Signage System 3.6.5 – Remote Code Execution

Tags: ,

[webapps] Mida eFramework 2.9.0 – Back Door Access

Posted by deepcore under Security (No Respond)

Mida eFramework 2.9.0 – Back Door Access

Tags: ,

[webapps] Seat Reservation System 1.0 – 'id' SQL Injection

Posted by deepcore under Security (No Respond)

Seat Reservation System 1.0 – ‘id’ SQL Injection

Tags: ,