Subscribe via feed.
Archive for June, 2021

VX Search 13.5.28 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

VX Search version 13.5.28 suffers from an unquoted service path vulnerability.

VeryFitPro 3.2.8 Insecure Transit

Posted by deepcore under exploit (No Respond)

VeryFitPro version 3.2.8 sends unencrypted cleartext transmission of sensitive information.

Samsung NPU npu_session_format Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

Samsung NPU (Neural Processing Unit) suffers from an out-of-bounds write vulnerability in npu_session_format.

Unified Office Total Connect Now 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Unified Office Total Connect Now version 1.0 suffers from a remote SQL injection vulnerability.

Trojan.Win32.Alien.erf Buffer Overflow

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Alien.erf malware suffers from a buffer overflow vulnerability.

Dup Scout 13.5.28 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Dup Scout version 13.5.28 suffers from an unquoted service path vulnerability.

Cisco HyperFlex HX Data Platform File Upload / Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated file upload vulnerability in Cisco HyperFlex HX Data Platform’s /upload endpoint to upload and execute a payload as the Tomcat user.

Microsoft SharePoint Unsafe Control And ViewState Remote Code Execution

Posted by deepcore under exploit (No Respond)

The EditingPageParser.VerifyControlOnSafeList method fails to properly validate user supplied data. This can be leveraged by an attacker to leak sensitive information in rendered-preview content. This module will leak the ViewState validation key and then use it to sign a crafted object that will trigger code execution when deserialized. Tested against SharePoint 2019 and SharePoint 2016, […]

Windows Kerberos AppContainer Enterprise Authentication Capability Bypass

Posted by deepcore under exploit (No Respond)

Kerberos supports a security buffer to set the target SPN of a ticket bypassing the SPN check in LSASS.

Windows Kerberos AppContainer Enterprise Authentication Capability Bypass

Posted by deepcore under exploit (No Respond)

Kerberos supports a security buffer to set the target SPN of a ticket bypassing the SPN check in LSASS.