Subscribe via feed.
Archive for April, 2021

Check Point Identity Agent Arbitrary File Write

Posted by deepcore under exploit (No Respond)

Check Point Identity Agent versions prior to R81.018.0000 allow for an arbitrary file overwrite action with escalated privileges.

DMA Radius Manager 4.4.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

DMA Radius Manager version 4.4.0 suffers from a cross site request forgery vulnerability.

Backdoor.Win32.Small.n Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Small.n malware suffers from a code execution vulnerability.

Tableau Server Open Redirection

Posted by deepcore under exploit (No Respond)

Tableau Server versions 2019.4-2019.4.17, 2020.1-2020.1.13, 2020.2-2020.2.10, 2020.3-2020.3.6, and 2020.4-2020.4.2 suffer from an open redirection vulnerability.

http://www.nongian.go.th/e0f.txt

Posted by deepcore under defacement (No Respond)

http://www.nongian.go.th/e0f.txt notified by Xyp3r2667

Tags:

https://www.bangwuakanarak.go.th/e0f.txt

Posted by deepcore under defacement (No Respond)

https://www.bangwuakanarak.go.th/e0f.txt notified by Xyp3r2667

Tags:

[webapps] PrestaShop 1.7.6.7 – 'location' Blind Sql Injection

Posted by deepcore under Security (No Respond)

PrestaShop 1.7.6.7 – ‘location’ Blind Sql Injection

Tags: ,

Google Chrome 81.0.4044 V8 Remote Code Execution

Posted by deepcore under exploit (No Respond)

An out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Google Chrome 86.0.4240 V8 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Insufficient data validation in V8 in Google Chrome versions prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Atlassian Jira Service Desk 4.9.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Atlassian Jira Service Desk version 4.9.1 suffers from a cross site scripting vulnerability via a file upload.