Subscribe via feed.
Archive for April, 2021

OpenEMR 5.0.2.1 Remote Code Execution

Posted by deepcore under exploit (No Respond)

OpenEMR version 5.0.2.1 remote code execution exploit that drops in a reverse shell.

Hasura GraphQL 1.3.3 Denial Of Service

Posted by deepcore under exploit (No Respond)

Hasura GraphQL version 1.3.3 suffers from a denial of service vulnerability.

Adtran Personal Phone Manager 10.8.1 DNS Exfiltration

Posted by deepcore under exploit (No Respond)

Adtran Personal Phone Manager version 10.8.1 suffers from a DNS exfiltration vulnerability.

Cockpit CMS 0.11.1 NoSQL Injection / Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits two NoSQL injection vulnerabilities to retrieve the user list and password reset tokens from the system. Next, the USER is targeted to reset their password. Then, a command injection vulnerability is used to execute the payload. While it is possible to upload a payload and execute it, the command injection provides […]

Nagios XI 5.7.3 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an OS command injection vulnerability in includes/components/nxti/index.php that enables an authenticated user with admin privileges to achieve remote code execution as the apache user. Valid credentials for a Nagios XI admin user are required. This module has been successfully tested against Nagios XI 5.7.3 running on CentOS 7.

GravCMS 1.10.7 Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary configuration write/update vulnerability to achieve remote code execution. Unauthenticated users can execute a terminal command under the context of the web server user. Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an […]

Zero-Day Vulns In SonicWall Email Security Are Being Exploited

Posted by deepcore under exploit (No Respond)

[remote] Tenda D151 & D301 – Configuration Download (Unauthenticated)

Posted by deepcore under Security (No Respond)

Tenda D151 & D301 – Configuration Download (Unauthenticated)

Tags: ,

[webapps] Discourse 2.7.0 – Rate Limit Bypass leads to 2FA Bypass

Posted by deepcore under Security (No Respond)

Discourse 2.7.0 – Rate Limit Bypass leads to 2FA Bypass

Tags: ,

[webapps] BlackCat CMS 1.3.6 – 'Multiple' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

BlackCat CMS 1.3.6 – ‘Multiple’ Stored Cross-Site Scripting (XSS)

Tags: ,