Subscribe via feed.
Archive for May, 2021

Voting System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Voting System version 1.0 suffers from remote time-based SQL injection vulnerability.

TYPO3 6.2.1 SQL Injection

Posted by deepcore under exploit (No Respond)

TYPO3 version 6.2.1 suffers from a remote SQL injection vulnerability.

Gadget Works Online Ordering System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Gadget Works Online Ordering System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Gadget Works Online Ordering System 1.0 SQL Injection / Code Execution

Posted by deepcore under exploit (No Respond)

Gadget Works Online Ordering System version 1.0 remote SQL injection to remote code execution exploit.

GitLab Community Edition (CE) 13.10.3 User Enumeration

Posted by deepcore under exploit (No Respond)

GitLab Community Edition (CE) version 13.10.3 suffers from multiple user enumeration vulnerabilities.

Epic Games Rocket League 1.95 Insecure Permissions

Posted by deepcore under exploit (No Respond)

Epic Games Rocket League versions 1.95 and below suffer from an insecure permissions vulnerability.

Epic Games Rocket League 1.95 Stack Buffer Overrun

Posted by deepcore under exploit (No Respond)

Epic Games Rocket League version 1.95 suffers from a stack-based buffer overflow vulnerability. The issue is caused due to a boundary error in the processing of a UPK format file, which can be exploited to cause a stack buffer overflow when a user crafts the file with a large array of bytes inserted in the […]

Google Chrome XOR Typer Out-Of-Bounds Access / Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an issue in the V8 engine on x86_x64 builds of Google Chrome versions prior to 89.0.4389.128/90.0.4430.72 when handling XOR operations in JIT’d JavaScript code. Successful exploitation allows an attacker to execute arbitrary code within the context of the V8 process. As the V8 process is normally sandboxed in the default configuration […]

IGEL OS Secure VNC/Terminal Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in IGEL OS Secure Terminal and Secure Shadow services.

[webapps] Anote 1.0 – XSS to RCE

Posted by deepcore under Security (No Respond)

Anote 1.0 – XSS to RCE

Tags: ,