Subscribe via feed.
Archive for April, 2021

ZBL EPON ONU Broadband Router 1.0 Remote Privilege Escalation

Posted by deepcore under exploit (No Respond)

ZBL EPON ONU Broadband Router version 1.0 suffers from a privilege escalation vulnerability. The limited administrative user (admin:admin) can elevate his/her privileges by sending a HTTP GET request to the configuration backup endpoint or the password page and disclose the http super user password. Once authenticated as super, an attacker will be granted access to […]

F5 BIG-IP 16.0.x Remote Code Execution

Posted by deepcore under exploit (No Respond)

F5 BIG-IP version 16.0.x suffers from an iControl REST remote code execution vulnerability.

Latrix 0.6.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Latrix version 0.6.0 suffers from a remote SQL injection vulnerability.

Company Crime Tracking Software 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Company Crime Tracking Software version 1.0 suffers from a persistent cross site scripting vulnerability.

phpPgAdmin 7.13.0 Command Execution

Posted by deepcore under exploit (No Respond)

phpPgAdmin version 7.13.0 suffers from an authenticated command execution vulnerability.

School Registration And Fee System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

School Registration and Fee System version 1.0 suffers from a remote blind SQL injection vulnerability.

School Registration And Fee System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

School Registration and Fee System version 1.0 suffers from persistent cross site scripting vulnerabilities.

ScadaBR 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

ScadaBR version 1.0 suffers from multiple remote shell upload vulnerabilities.

SaltStack Salt API Unauthenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module leverages an authentication bypass and directory traversal vulnerabilities in Saltstack Salt’s REST API to execute commands remotely on the master as the root user. Every 60 seconds, salt-master service performs a maintenance process check that reloads and executes all the grains on the master, including custom grain modules in the Extension Module […]

F5 iControl Server-Side Request Forgery / Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a pre-authentication server-side request forgery vulnerability in the F5 iControl REST API’s /mgmt/shared/authn/login endpoint to generate an X-F5-Auth-Token that can be used to execute root commands on an affected BIG-IP or BIG-IQ device.