Subscribe via feed.
Archive for November, 2020

Oracle WebLogic Server Administration Console Handle Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a path traversal and a Java class instantiation in the handle implementation of WebLogic’s Administration Console to execute code as the WebLogic user. Versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 are known to be affected. Tested against 12.2.1.3.0 from Vulhub (Linux) and on Windows. Warning! Multiple sessions may be created by […]

[local] Zortam Mp3 Media Studio 27.60 – Remote Code Execution (SEH)

Posted by deepcore under Security (No Respond)

Zortam Mp3 Media Studio 27.60 – Remote Code Execution (SEH)

Tags: ,

[webapps] WonderCMS 3.1.3 – 'content' Persistent Cross-Site Scripting

Posted by deepcore under Security (No Respond)

WonderCMS 3.1.3 – ‘content’ Persistent Cross-Site Scripting

Tags: ,

https://www.tphcp.go.th/ah.html

Posted by deepcore under defacement (No Respond)

https://www.tphcp.go.th/ah.html notified by Al Catraz

Tags:

Complaint Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Complaint Management System version 1.0 suffers from a remote shell upload vulnerability.

WordPress Fancy Product Designer For WooCommerce Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Fancy Product Designer for WooCommerce plugin versions prior to 4.5.1 suffer from a persistent cross site scripting vulnerability.

WordPress Fancy Product Designer For WooCommerce 4.5.1 File Upload

Posted by deepcore under exploit (No Respond)

WordPress Fancy Product Designer for WooCommerce plugin versions 4.5.1 and below suffer from an unauthenticated arbitrary file upload vulnerability.

Avaya Web License Manager XML Injection

Posted by deepcore under exploit (No Respond)

Avaya Web License Manager versions 6.x, 7.0 through 7.1.3.6, and 8.0 through 8.1.2.0.0 suffer from a blind out-of-band XML external entity injection vulnerability.

WordPress WP Forms 1.6.3.1 Cross SIte Scripting

Posted by deepcore under exploit (No Respond)

WordPress WP Forms plugin version 1.6.3.1 suffers from a persistent cross site scripting vulnerability.

Zerologon Netlogon Privilege Escalation

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for the ZeroLogin Netlogon privilege escalation vulnerability.