Subscribe via feed.
Archive for October, 2020

[webapps] Employee Management System 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Employee Management System 1.0 – Authentication Bypass

Tags: ,

Chrome MediaElementEventListener::UpdateSources Use-After-Free

Posted by deepcore under exploit (No Respond)

Chrome suffers from a MediaElementEventListener::UpdateSources use-after-free vulnerability.

TimeClock Software 1.01 SQL Injection

Posted by deepcore under exploit (No Respond)

TimeClock Software version 1.01 suffers from an authenticated time-based remote SQL injection vulnerability.

NodeBB Forum 1.14.2 Account Takeover

Posted by deepcore under exploit (No Respond)

NodeBB Forum versions 1.12.2 through 1.14.2 suffer from an account takeover vulnerability.

Guild Wars 2 Insecure Folder Permissions

Posted by deepcore under exploit (No Respond)

Guild Wars 2 suffers from an insecure folder permissions vulnerability.

[webapps] rConfig 3.9.5 – Remote Code Execution (Unauthenticated)

Posted by deepcore under Security (No Respond)

rConfig 3.9.5 – Remote Code Execution (Unauthenticated)

Tags: ,

[webapps] Vehicle Parking Management System 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

Vehicle Parking Management System 1.0 – Authentication Bypass

Tags: ,

berliCRM 1.0.24 SQL Injection

Posted by deepcore under exploit (No Respond)

berliCRM version 1.0.24 suffers from a remote SQL injection vulnerability.

Battle.Net 1.27.1.12428 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

Battle.Net version 1.27.1.12428 suffers from a privilege escalation vulnerability due to insecure file permissions.

xls2csv 0.95 Overflow / Memory Leak

Posted by deepcore under exploit (No Respond)

xls2csv version 0.95 suffers from three overflow, one malloc fail, one memory leak, and two null pointer dereference vulnerabilities. Proof of concept code and ASAN analysis is included.