Subscribe via feed.
Archive for January, 2021

Packed.Win32.Katusha.o Insecure Permissions

Posted by deepcore under exploit (No Respond)

Packed.Win32.Katusha.o suffers from an insecure permissions vulnerability.

Metasploit Framework 6.0.11 Command Injection

Posted by deepcore under exploit (No Respond)

Metasploit Framework version 6.0.11 msfvenom APK template command injection exploit.

http://www.prachuap.go.th/vin.txt

Posted by deepcore under defacement (No Respond)

http://www.prachuap.go.th/vin.txt notified by Imkey7

Tags:

EgavilanMedia PHPCRUD 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

EgavilanMedia PHPCRUD version 1.0 suffers from a persistent cross site scripting vulnerability.

CMSUno 1.6.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

CMSUno version 1.6.2 authenticated remote code execution exploit. The original discovery for the vulnerability leveraged is attributed to Fatih Celik in November of 2020.

jQuery UI 1.12.1 Denial Of Service

Posted by deepcore under exploit (No Respond)

jQuery UI version 1.12.1 suffers from a denial of service vulnerability.

WordPress SuperForms 4.9 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress SuperForms plugin version 4.9 suffers from a remote shell upload vulnerability.

Chamilo LMS 1.11.14 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Chamilo LMS version 1.11.14 suffers from a cross site scripting vulnerability.

Micro Focus UCMDB Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits two vulnerabilities, that when chained allow an attacker to achieve unauthenticated remote code execution in Micro Focus UCMDB. UCMDB included in versions 2020.05 and below of Operations Bridge Manager are affected, but this module can probably also be used to exploit Operations Bridge Manager (containerized) and Application Performance Management.

PRTG Network Monitor Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authenticated remote code execution vulnerability in PRTG Network Monitor. Notifications can be created by an authenticated user and can execute scripts when triggered. Due to a poorly validated input on the script name, it is possible to chain it with a user-supplied command allowing command execution under the context of […]