Subscribe via feed.
Archive for May, 2021

http://kshos.go.th/readme.html

Posted by deepcore under defacement (No Respond)

http://kshos.go.th/readme.html notified by Unknown45

Tags:

http://wihanhosp.go.th/readme.html

Posted by deepcore under defacement (No Respond)

http://wihanhosp.go.th/readme.html notified by Unknown45

Tags:

Mozilla Firefox 88.0.1 File Extension Execution

Posted by deepcore under exploit (No Respond)

Mozilla Firefox versions 88.0.1 and below suffer from an issue that allows for execution of a file holding arbitrary code just by downloading it.

Microsoft Exchange ProxyLogon Collector

Posted by deepcore under exploit (No Respond)

This Metasploit module scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin by chaining this bug with another post-auth arbitrary-file-write vulnerability to get code execution. As a result, an unauthenticated attacker can execute arbitrary commands on Microsoft Exchange Server. This vulnerability affects Exchange 2013 […]

libX11 Insufficient Length Check / Injection

Posted by deepcore under exploit (No Respond)

A missing length check in libX11 allows data from LookupColor requests to mess up the client-server communication protocol and inject malicious X server requests.

WordPress WP Statistics 13.0.7 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress WP Statistics plugin versions 13.0 to 13.0.7 suffer from a remote unauthenticated blind SQL injection vulnerability.

DELL dbutil_2_3.sys 2.3 Arbitrary Write / Privilege Escalation

Posted by deepcore under exploit (No Respond)

DELL dbutil_2_3.sys version 2.3 arbitrary write to local privilege escalation exploit.

DELL dbutil_2_3.sys 2.3 Arbitrary Write / Privilege Escalation

Posted by deepcore under exploit (No Respond)

DELL dbutil_2_3.sys version 2.3 arbitrary write to local privilege escalation exploit.

ASUS HID Access Service 1.0.94.0 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

ASUS HID Access Service version 1.0.94.0 suffers an unquoted service path vulnerability.

Microsoft HTTP Protocol Stack Remote Code Execution

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for the HTTP protocol stack remote code execution vulnerability related to a use-after-free dereference in http.sys.