Subscribe via feed.
Archive for January, 2021

ECSIMAGING PACS 6.21.5 SQL Injection

Posted by deepcore under exploit (No Respond)

ECSIMAGING PACS version 6.21.5 suffers from a remote SQL injection vulnerability.

dnsrecon 0.10.0 CSV Injection

Posted by deepcore under exploit (No Respond)

dnsrecon version 0.10.0 suffers from a CSV injection vulnerability.

Online Doctor Appointment System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Doctor Appointment System version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.

Backdoor.Win32.Agent.dcbh Insecure Permissions / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Agent.dcbh malware suffers from an insecure permissions vulnerability that can allow for privilege escalation.

Cockpit 234 Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

Cockpit version 234 suffers from an unauthenticated server-side request forgery vulnerability.

Backdoor.Win32.Xtreme.yvp Insecure Permissions / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Xtreme.yvp malware suffers from an insecure permissions vulnerability that can allow for privilege escalation.

WordPress wpDiscuz 7.0.4 Shell Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload in the WordPress wpDiscuz plugin version 7.0.4. This flaw gave unauthenticated attackers the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable server.

Backdoor.Win32.NinjaSpy.c Remote Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.NinjaSpy.c suffers from a remote stack buffer overflow vulnerability. The specimen drops a DLL named “cmd.dll” under C:WINDOWS which listens on both TCP ports 2003 and 2004. By sending consecutive HTTP PUT requests with large payloads of characters, we can cause buffer overflow.

PaperStream IP (TWAIN) 1.42.0.5685 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

PaperStream IP (TWAIN) version 1.42.0.5685 suffers from a local privilege escalation vulnerability.

Gitea 1.7.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Gitea version 1.7.5 suffers from a remote code execution vulnerability.