Subscribe via feed.
Archive for April, 2021

ExpressVPN VPN Router 1.0 Integer Overflow

Posted by deepcore under exploit (No Respond)

ExpressVPN VPN Router version 1.0 suffers from an integer overflow vulnerability.

Chrome V8 JavaScript Engine Remote Code Execution

Posted by deepcore under exploit (No Respond)

Chrome V8 Javascript Engine remote code execution zero day exploit. Google is expected to release an update to their browser on tuesday 04/14/2021 that will address this vulnerability.

Blitar Tourism 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Blitar Tourism version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Microsoft Windows SCM Remote Access Check Limit Bypass Privilege Escalation

Posted by deepcore under exploit (No Respond)

The access limit check for non-local admins when accessing the SCM remotely can be bypassed by requesting MAXIMUM_ALLOWED, leading to gaining access to start services etc.

Nagios XI getprofile.sh Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability in the getprofile.sh script of Nagios XI versions prior to 5.6.6 in order to upload a malicious check_ping plugin and thereby execute arbitrary commands. For Nagios XI 5.2.0 through 5.4.13, the commands are run as the nagios user. For versions 5.5.0 through 5.6.5, the commands are run as root. […]

jQuery 1.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

jQuery version 1.2 suffers from a cross site scripting vulnerability.

jQuery 1.0.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

jQuery version 1.0.3 suffers from a cross site scripting vulnerability.

Digital Crime Report Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Digital Crime Report Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Trojan.Win32.Jorik.qje Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Jorik.qje malware suffers from an insecure permissions vulnerability.

Genexis PLATINUM 4410 2.1 P4410-V2-1.28 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Genexis PLATINUM 4410 version 2.1 P4410-V2-1.28 suffers from a remote command execution vulnerability.