Subscribe via feed.
Archive for July, 2021

Vianeos OctoPUS 5 SQL Injection

Posted by deepcore under exploit (No Respond)

Vianeos OctoPUS version 5 suffers from a remote time-based SQL injection vulnerability.

Online Voting System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Voting System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Online Voting System 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Online Voting System version 1.0 suffers from an authenticated remote code execution vulnerability.

WinWaste.NET 1.0.6183.16475 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

WinWaste.NET version 1.0.6183.16475 allows a local unprivileged user to replace the executable with a malicious file that will be executed with LocalSystem privileges.

WordPress XCloner 4.2.12 Remote Code Execution

Posted by deepcore under exploit (No Respond)

WordPress XCloner plugin version 4.2.12 authenticated remote code execution exploit.

Docker Container Escape

Posted by deepcore under exploit (No Respond)

This Metasploit module leverages a flaw in runc to escape a Docker container and get command execution on the host as root. This vulnerability is identified as CVE-2019-5736. It overwrites the runc binary with the payload and waits for someone to use docker exec to get into the container. This will trigger the payload execution. […]

Packet Storm New Exploits For June, 2021

Posted by deepcore under exploit (No Respond)

This archive contains all of the 217 exploits added to Packet Storm in June, 2021.

[local] WinWaste.NET 1.0.6183.16475 – Privilege Escalation due Incorrect Access Control

Posted by deepcore under Security (No Respond)

WinWaste.NET 1.0.6183.16475 – Privilege Escalation due Incorrect Access Control

Tags: ,

[webapps] b2evolution 7.2.2 – 'edit account details' Cross-Site Request Forgery (CSRF)

Posted by deepcore under Security (No Respond)

b2evolution 7.2.2 – ‘edit account details’ Cross-Site Request Forgery (CSRF)

Tags: ,

[webapps] AKCP sensorProbe SPX476 – 'Multiple' Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

AKCP sensorProbe SPX476 – ‘Multiple’ Cross-Site Scripting (XSS)

Tags: ,