Subscribe via feed.
Archive for February, 2021

LogonExpert 8.1 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

LogonExpert version 8.1 suffers from an unquoted service path vulnerability.

Softros LAN Messenger 9.6.4 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Softros LAN Messenger version 9.6.4 suffers from an unquoted service path vulnerability.

SLMail 5.1.0.4420 Remote Code Execution

Posted by deepcore under exploit (No Respond)

SLMail version 5.1.0.4420 remote code execution exploit.

Microsoft Exchange Server msExchEcpCanary CSRF / Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Exchange Server has a flaw that exists within the HasValidCanary function inside of the Canary15 class. The issue results in an insecure generation of cross site request forgery tokens that can be used to install an office-addins. An attacker can leverage this vulnerability to escalate privileges to an administrative account.

VMware vCenter 6.5 / 7.0 Remote Code Execution Proof Of Concept

Posted by deepcore under exploit (No Respond)

VMware vCenter version 6.5 and 7.0 remote code execution proof of concept exploit.

Backdoor.Win32.Agent.xw Denial Of Service / Null Pointer

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Agent.xw malware suffers from denial of service and null pointer vulnerabilities.

Python jsonpickle 2.0.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Python jsonpickle version 2.0.0 suffers from a remote code execution vulnerability.

LayerBB 1.1.4 SQL Injection

Posted by deepcore under exploit (No Respond)

LayerBB version 1.1.4 suffers from a remote SQL injection vulnerability.

Backdoor.Win32.Delf.adag Hardcoded Credentials / Traversal

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Delf.adag malware suffers from hardcoded credential and traversal vulnerabilities.

Unified Remote 3.9.0.2463 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Unified Remote version 3.9.0.2463 suffers from a remote code execution vulnerability.