Subscribe via feed.
Archive for August, 2021

[webapps] RaspAP 2.6.6 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

RaspAP 2.6.6 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

[webapps] Simple Phone book/directory 1.0 – 'Username' SQL Injection (Unauthenticated)

Posted by deepcore under Security (No Respond)

Simple Phone book/directory 1.0 – ‘Username’ SQL Injection (Unauthenticated)

Tags: ,

[webapps] Online Traffic Offense Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)

Posted by deepcore under Security (No Respond)

Online Traffic Offense Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)

Tags: ,

https://www.ccit.go.th/azu.php

Posted by deepcore under defacement (No Respond)

https://www.ccit.go.th/azu.php notified by Wedus

Tags:

Laundry Booking Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Laundry Booking Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Laundry Booking Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Laundry Booking Management System version 1.0 suffers from a remote SQL injection vulnerability.

NetModule Router Software Password Handling / Session Fixation

Posted by deepcore under exploit (No Respond)

NetModule Router Software versions prior to 4.3.0.113, 4.4.0.111, and 4.5.0.105 suffer from insecure password handling and session fixation vulnerabilities.

Online Traffic Offense Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Traffic Offense Management System version 1.0 suffers from a remote SQL injection vulnerability.

Microsoft Exchange ProxyShell Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability on Microsoft Exchange Server that allows an attacker to bypass the authentication, impersonate an arbitrary user, and write an arbitrary file to achieve remote code execution. By taking advantage of this vulnerability, you can execute arbitrary commands on the remote Microsoft Exchange Server. This vulnerability affects Exchange 2013 CU23 […]

Microsoft Exchange ProxyShell Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability on Microsoft Exchange Server that allows an attacker to bypass the authentication, impersonate an arbitrary user, and write an arbitrary file to achieve remote code execution. By taking advantage of this vulnerability, you can execute arbitrary commands on the remote Microsoft Exchange Server. This vulnerability affects Exchange 2013 CU23 […]