Subscribe via feed.
Archive for March, 2021

Hotel And Lodge Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Hotel And Lodge Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

WordPress GiveWP 2.9.7 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress GiveWP plugin version 2.9.7 suffers from a cross site scripting vulnerability.

Advantech iView Unauthenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated configuration change combined with an unauthenticated file write primitive, leading to an arbitrary file write that allows for remote code execution as the user running iView, which is typically NT AUTHORITYSYSTEM. This issue was demonstrated in the vulnerable version 5.7.02.5992 and fixed in version 5.7.03.6112.

Microsoft Exchange ProxyLogon Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication, impersonating as the admin (CVE-2021-26855) and write arbitrary file (CVE-2021-27065) to get the RCE (Remote Code Execution). By taking advantage of this vulnerability, you can execute arbitrary commands on the remote Microsoft Exchange Server. This vulnerability affects Exchange […]

[local] Ext2Fsd v0.68 – 'Ext2Srv' Unquoted Service Path

Posted by deepcore under Security (No Respond)

Ext2Fsd v0.68 – ‘Ext2Srv’ Unquoted Service Path

Tags: ,

CMS Made Simple 2.2.15 SQL Injection

Posted by deepcore under exploit (No Respond)

CMS Made Simple version 2.2.15 suffers from a remote SQL injection vulnerability.

CMS Made Simple 2.2.15 Shell Upload

Posted by deepcore under exploit (No Respond)

CMS Made Simple version 2.2.15 suffers from a remote shell upload vulnerability.

Winpakpro 4.8 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Winpakpro version 4.8 suffers from multiple unquoted service path vulnerabilities.

SAPSetup Automatic Workstation Update Service 750 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

SAPSetup Automatic Workstation Update Service 750 suffers from an unquoted service path vulnerability.

Zoom 5.4.3 (54779.1115) / 5.5.4 (13142.0301) Information Disclosure

Posted by deepcore under exploit (No Respond)

Zoom versions 5.4.3 (54779.1115) and 5.5.4 (13142.0301) temporarily shares other application windows not in scope for sharing.