Subscribe via feed.
Archive for July, 2021

Backdoor.Win32.Agent.cu Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Agent.cu malware suffers from a code execution vulnerability.

Backdoor.Win32.PsyRat.b Denial Of Service

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.PsyRat.b malware suffers from a denial of service vulnerability.

NoteBurner 2.35 Denial Of Service

Posted by deepcore under exploit (No Respond)

NoteBurner version 2.35 suffers from a denial of service vulnerability.

Backdoor.Win32.PsyRat.b Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.PsyRat.b malware suffers from a code execution vulnerability.

WordPress Modern Events Calendar Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module allows an attacker with a privileged WordPress account to launch a reverse shell due to an arbitrary file upload vulnerability in WordPress Modern Events Calendar plugin versions prior to 5.16.5. This is due to an incorrect check of the uploaded file extension. Indeed, by using text/csv content-type in a request, it is […]

Backdoor.Win32.Bifrose.acci Buffer Overflow

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Bifrose.acci malware suffers from a buffer overflow vulnerability that can allow for code execution.

Backdoor.Win32.Nbdd.bgz Buffer Overflow

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Nbdd.bgz malware suffers from a buffer overflow vulnerability.

WordPress SP Project And Document Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module allows an attacker with a privileged WordPress account to launch a reverse shell due to an arbitrary file upload vulnerability in WordPress SP Project and Document plugin versions prior to 4.22. The security check only searches for lowercase file extensions such as .php, making it possible to upload .pHP files for instance. […]

[webapps] PHP 7.3.15-3 – 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection

Posted by deepcore under Security (No Respond)

PHP 7.3.15-3 – ‘PHP_SESSION_UPLOAD_PROGRESS’ Session Data Injection

Tags: ,

[webapps] Customer Relationship Management System (CRM) 1.0 – Sql Injection Authentication Bypass

Posted by deepcore under Security (No Respond)

Customer Relationship Management System (CRM) 1.0 – Sql Injection Authentication Bypass

Tags: ,