Subscribe via feed.
Archive for November, 2020

Foxit Reader 9.0.1.1049 Arbitrary Code Execution

Posted by deepcore under exploit (No Respond)

Foxit Reader version 9.0.1.1049 suffers from an arbitrary code execution vulnerability. This is a variant exploit of the original finding from 2018.

Pure-FTPd 1.0.48 Remote Denial Of Service

Posted by deepcore under exploit (No Respond)

Pure-FTPd version 1.0.48 suffers from a denial of service vulnerability.

Razer Chroma SDK Server 3.16.02 Race Condition

Posted by deepcore under exploit (No Respond)

Razer Chroma SDK Server version 3.16.02 suffers from a race condition vulnerability that allows for remote file execution.

BigBlueButton 2.2.29 E-mail Validation Bypass

Posted by deepcore under exploit (No Respond)

BigBlueButton versions 2.2.29 and below suffer from an e-mail validation bypass vulnerability.

libupnp 1.6.18 Denial Of Service

Posted by deepcore under exploit (No Respond)

libupnp version 1.6.18 stack-based buffer overflow denial of service exploit.

Fujitsu Eternus Storage DX200 S4 Broken Authentication

Posted by deepcore under exploit (No Respond)

Fujitsu Eternus Storage DX200 S4 fails to set cookies for authentication allowing for replay of URLs to achieve root level privileges.

ElkarBackup 1.3.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ElkarBackup version 1.3.3 suffers from persistent cross site scripting vulnerabilities. This notes a variant attack vector for the original vulnerability discovered in this version in August of 2020 by Enes Ozeser.

SAP Lumira 1.31 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SAP Lumira version 1.31 suffers from a persistent cross site scripting vulnerability.

Laravel Administrator 4 File Upload

Posted by deepcore under exploit (No Respond)

Laravel Administrator version 4 suffers from an unrestricted file upload vulnerability.

Moodle 3.8 Arbitary File Upload

Posted by deepcore under exploit (No Respond)

Moodle version 3.8 suffers from an arbitrary file upload vulnerability.