Subscribe via feed.
Archive for November, 2020

http://therapy.huahinhospital.go.th

Posted by deepcore under defacement (No Respond)

http://therapy.huahinhospital.go.th notified by Al Catraz

Tags:

Mysterious Bugs Were Used To Hack iPhones and Android Phones And No One Will Talk About It

Posted by deepcore under exploit (No Respond)

Microsoft November 2020 Patch Arrives With Fix For Windows Zero Day

Posted by deepcore under exploit (No Respond)

[webapps] WordPress Plugin Good LMS 2.1.4 – 'id' Unauthenticated SQL Injection

Posted by deepcore under Security (No Respond)

WordPress Plugin Good LMS 2.1.4 – ‘id’ Unauthenticated SQL Injection

Tags: ,

[webapps] Water Billing System 1.0 – 'username' and 'password' parameters SQL Injection

Posted by deepcore under Security (No Respond)

Water Billing System 1.0 – ‘username’ and ‘password’ parameters SQL Injection

Tags: ,

Car Rental Management System 1.0 Shell Upload / SQL Injection

Posted by deepcore under exploit (No Respond)

Car Rental Management System version 1.0 remote SQL injection and shell upload exploit.

ShoreTel Conferencing 19.46.1802.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ShoreTel Conferencing version 19.46.1802.0 suffers from a cross site scripting vulnerability.

Anuko Time Tracker 1.19.23.5325 CSV Injection

Posted by deepcore under exploit (No Respond)

Anuko Time Tracker version 1.19.23.5325 suffers from a CSV formula injection vulnerability.

WordPress File Manager 6.8 Remote Code Execution

Posted by deepcore under exploit (No Respond)

The WordPress File Manager (wp-file-manager) plugin versions 6.0 through 6.8 allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the […]

Rapid7 Metasploit Framework msfvenom APK Template Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in Metasploit Framework’s msfvenom payload generator when using a crafted APK file as an Android payload template. Affected includes Metasploit Framework versions 6.0.11 and below and Metasploit Pro versions 4.18.0 and below.