Subscribe via feed.
Archive for October, 2020

Sony IPELA Network Camera Remote Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

Sony IPELA Network Camera SNC-DH120T version 1.82.01 suffers from a remote stack buffer overflow vulnerability. The vulnerability is caused due to a boundary error in the processing of received FTP traffic through the FTP client functionality (ftpclient.cgi), which can be exploited to cause a stack-based buffer overflow when a user issues a POST request to […]

Safari Type Confusion / Sandbox Escape

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an incorrect side-effect modeling of the ‘in’ operator. The DFG compiler assumes that the ‘in’ operator is side-effect free, however the embed element with the PDF plugin provides a callback that can trigger side-effects leading to type confusion (CVE-2020-9850). The type confusion can be used as addrof and fakeobj primitives that […]

[webapps] Photo Share Website 1.0 – Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

Photo Share Website 1.0 – Persistent Cross-Site Scripting

Tags: ,

[webapps] MedDream PACS Server 6.8.3.751 – Remote Code Execution (Authenticated)

Posted by deepcore under Security (No Respond)

MedDream PACS Server 6.8.3.751 – Remote Code Execution (Authenticated)

Tags: ,

Corona Exposure Notifications API Data Leakage

Posted by deepcore under exploit (No Respond)

It appears that the corona virus Exposure Notifications API for iOS and Android may have a data leakage issue.

BearShare Lite 5.2.5 Buffer Overflow

Posted by deepcore under exploit (No Respond)

BearShare Lite version 5.2.5 buffer overflow proof of concept exploit.

WebsiteBaker 2.12.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

WebsiteBaker version 2.12.2 suffers from a remote code execution vulnerability.

Qiata FTA 1.70.19 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Qiata FTA versions 1.70.19 and below suffer from a cross site scripting vulnerability.

DOMOS 5.8 Command Injection

Posted by deepcore under exploit (No Respond)

DOMOS versions 5.8 and below suffer from a command injection vulnerability.

MailDepot 2032 SP2 Session Expiration

Posted by deepcore under exploit (No Respond)

MailDepot version 2032 SP2 (2.2.1242) suffers from a session expiration design issue.