Subscribe via feed.
Archive for July, 2021

Backdoor.Win32.NerTe.781 Authentication Bypass / Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.NerTe.781 malware suffers from bypass and code execution vulnerabilities.

Visual Tools DVR VX16 4.2.28.0 Command Injection

Posted by deepcore under exploit (No Respond)

Visual Tools DVR VX16 version 4.2.28.0 suffers from a command injection vulnerability.

perfexcrm 1.10 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

perfexcrm version 1.10 suffers from a persistent cross site scripting vulnerability.

Pallets Werkzeug 0.15.4 Path Traversal

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for a path traversal vulnerability in Pallets Werkzeug version 0.15.4.

WordPress Anti-Malware Security And Bruteforce Firewall 4.20.59 Directory Traversal

Posted by deepcore under exploit (No Respond)

WordPress Anti-Malware Security and Bruteforce Firewall plugin version 4.20.59 suffers from a directory traversal vulnerability.

Phone Shop Sales Managements System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Phone Shop Sales Managements System version 1.0 shell upload exploit. This is a variant of the original discovery made in this version of the software by Richard Jones in April of 2021.

Phone Shop Sales Managements System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Billing System Project 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Billing System Project version 1.0 suffers from a remote shell upload vulnerability.

Exam Hall Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Exam Hall Management System version 1.0 suffers from an unauthenticated remote shell upload vulnerability.

NSClient++ 0.5.2.35 Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module allows an attacker with an unprivileged windows account to gain admin access on windows system and start a shell. For this module to work, both the NSClient++ web interface and ExternalScripts features must be enabled. You must also know where the NSClient config file is, as it is used to read the […]