Subscribe via feed.
Archive for January, 2021

Backdoor.Win32.Zombam.a Remote Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Zombam.a malware suffers from a remote stack buffer overflow vulnerability.

SmartAgent 3.1.0 Privilege Escalation

Posted by deepcore under exploit (No Respond)

SmartAgent version 3.1.0 suffers from a privilege escalation vulnerability.

Cemetery Mapping And Information System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Cemetery Mapping and Information System version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Gila CMS 2.0.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Gila CMS version 2.0.0 suffers from a remote code execution vulnerability.

WordPress AIT CSV Import/Export 3.0.3 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress AIT CSV Import/Export plugin versions 3.0.3 and below allow unauthenticated remote attackers to upload and execute arbitrary PHP code. The upload-handler does not require authentication, nor validates the uploaded content. It may return an error when attempting to parse a CSV, however the uploaded shell is left. The shell is uploaded to wp-content/uploads/. The […]

Cloud Filter Arbitrary File Creation / Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in cldflt.sys. The Cloud Filter driver on Windows 10 v1803 and later, prior to the December 2020 updates, did not set the IO_FORCE_ACCESS_CHECK or OBJ_FORCE_ACCESS_CHECK flags when calling FltCreateFileEx() and FltCreateFileEx2() within its HsmpOpCreatePlaceholders() function with attacker controlled input. This meant that files were created with KernelMode permissions, thereby […]

http://www.banon-ngao.go.th/z.htm

Posted by deepcore under defacement (No Respond)

http://www.banon-ngao.go.th/z.htm notified by Xyp3r2667

Tags:

http://bgr11.dgr.go.th/bots.txt

Posted by deepcore under defacement (No Respond)

http://bgr11.dgr.go.th/bots.txt notified by Xyp3r2667

Tags:

http://bgr12.dgr.go.th/bots.txt

Posted by deepcore under defacement (No Respond)

http://bgr12.dgr.go.th/bots.txt notified by Xyp3r2667

Tags:

[remote] Erlang Cookie – Remote Code Execution

Posted by deepcore under Security (No Respond)

Erlang Cookie – Remote Code Execution

Tags: ,