Subscribe via feed.
Archive for October, 2020

Sphider Search Engine 1.3.6 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Sphider Search Engine version 1.3.6 remote code execution exploit.

Adtec Digital Products Hardcoded Credentials / Remote Root

Posted by deepcore under exploit (No Respond)

Adtec Digital is a leading manufacturer of Broadcast, Cable and IPTV products and solutions. Many of their devices utilize hard-coded and default credentials within its Linux distribution image for Web/Telnet/SSH access. A remote attacker could exploit this vulnerability by logging in using the default credentials for accessing the web interface or gain shell access as […]

Sentrifugo 3.2 Shell Upload / Restriction Bypass

Posted by deepcore under exploit (No Respond)

Sentrifugo version 3.2 suffers from a restriction bypass vulnerability that allows for a remote shell upload.

TDM Digital Signage PC Player 4.1 Insecure File Permissions

Posted by deepcore under exploit (No Respond)

TDM Digital Signage Windows Player version 4.1 suffers from an elevation of privileges vulnerability which can be used by a simple authenticated user that can change the executable file with a binary of choice.

[webapps] CSE Bookstore 1.0 – Authentication Bypass

Posted by deepcore under Security (No Respond)

CSE Bookstore 1.0 – Authentication Bypass

Tags: ,

[webapps] Nagios XI 5.7.3 – 'mibs.php' Remote Command Injection (Authenticated)

Posted by deepcore under Security (No Respond)

Nagios XI 5.7.3 – ‘mibs.php’ Remote Command Injection (Authenticated)

Tags: ,

CMS Made Simple 2.1.6 Server-Side Template Injection

Posted by deepcore under exploit (No Respond)

CMS Made Simple version 2.1.6 suffers from a server-side template injection vulnerability.

PDW File Browser 1.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PDW File Browser versions 1.3 and below suffer from a cross site scripting vulnerability.

InoERP 0.7.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

InoERP version 0.7.2 suffers from an unauthenticated remote code execution vulnerability.

Online Health Care System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Health Care System version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.