Subscribe via feed.
Archive for October, 2020

Hashicorp Vault AWS IAM Integration Authentication Bypass

Posted by deepcore under exploit (No Respond)

HashiCorp Vault’s AWS IAM authentication method can be bypassed by sending a serialized request to the STS AssumeRoleWithWebIdentity method as part of the authentication flow. The request triggers a JSON encoded response from the STS server, which can contain a fully-attacker controlled fake GetCallerIdentityResponse as part of its body. As the Vault response parser ignores […]

Hashicorp Vault GCP IAM Integration Authentication Bypass

Posted by deepcore under exploit (No Respond)

HashiCorp Vault’s GCP authentication method can be bypassed on gce type roles that do not specify bound_service_accounts. Vault does not enforce that the compute_engine data in a signed JWT token has any relationship to the service account that created the token. This makes it possible to impersonate arbitrary GCE instances, by creating a JWT token […]

http://www.klonghok.go.th

Posted by deepcore under defacement (No Respond)

http://www.klonghok.go.th notified by Tev3R

Tags:

Tenda Router Zero-Days Emerge In Spyware Botnet Campaign

Posted by deepcore under exploit (No Respond)

[dos] BACnet Test Server 1.01 – Remote Denial of Service (PoC)

Posted by deepcore under Security (No Respond)

BACnet Test Server 1.01 – Remote Denial of Service (PoC)

Tags: ,

[webapps] Textpattern CMS 4.6.2 – 'body' Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

Textpattern CMS 4.6.2 – ‘body’ Persistent Cross-Site Scripting

Tags: ,

SpamTitan 7.07 Remote Code Execution

Posted by deepcore under exploit (No Respond)

SpamTitan version 7.07 suffers from an unauthenticated remote code execution vulnerability in snmp-x.php.

Restaurant Reservation System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Restaurant Reservation System version 1.0 suffers from an authenticated remote SQL injection vulnerability.

[webapps] EasyPMS 1.0.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

EasyPMS 1.0.0 – Authentication Bypass

Tags: ,

[webapps] Karel IP Phone IP1211 Web Management Panel – Directory Traversal

Posted by deepcore under Security (No Respond)

Karel IP Phone IP1211 Web Management Panel – Directory Traversal

Tags: ,