Subscribe via feed.
Archive for August, 2021

Charity Management System CMS 1.0 Code Execution / XSS / SQL Injection

Posted by deepcore under exploit (No Respond)

Charity Management System CMS version 1.0 suffers from code execution, cross site scripting, and remote SQL injection vulnerabilities.

WebKit WebCore::FrameLoader::PolicyChecker::checkNavigationPolicy Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a heap use-after-free vulnerability in WebCore::FrameLoader::PolicyChecker::checkNavigationPolicy.

JavaScriptCore Crash Proof Of Concept

Posted by deepcore under exploit (No Respond)

JavaScriptCore suffers from a crash condition due to an uninitialized register in slow_path_profile_catch. Proof of concept that affects Safari is included.

WebKit Element::dispatchMouseEvent Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a heap use-after-free vulnerability in Element::dispatchMouseEvent.

Altus Sistemas de Automacao Products CSRF / Command Injection / Hardcoded Credentials

Posted by deepcore under exploit (No Respond)

Multiple Altus Sistemas de Automacao products such as the Nexto NX30xx Series, Nexto NX5xxx Series, Nexto Xpress XP3xx Series, and Hadron Xtorm HX3040 Series suffer from command injection, cross site request forgery, and hardcoded credential vulnerabilities.

[webapps] Laundry Booking Management System 1.0 – 'Multiple' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

Laundry Booking Management System 1.0 – ‘Multiple’ Stored Cross-Site Scripting (XSS)

Tags: ,

[webapps] Laundry Booking Management System 1.0 – 'Multiple' SQL Injection

Posted by deepcore under Security (No Respond)

Laundry Booking Management System 1.0 – ‘Multiple’ SQL Injection

Tags: ,

[webapps] Online Traffic Offense Management System 1.0 – 'id' SQL Injection (Authenticated)

Posted by deepcore under Security (No Respond)

Online Traffic Offense Management System 1.0 – ‘id’ SQL Injection (Authenticated)

Tags: ,

Altus Sistemas de Automacao Products CSRF / Command Injection / Hardcoded Credentials

Posted by deepcore under exploit (No Respond)

Multiple Altus Sistemas de Automacao products such as the Nexto NX30xx Series, Nexto NX5xxx Series, Nexto Xpress XP3xx Series, and Hadron Xtorm HX3040 Series suffer from command injection, cross site request forgery, and hardcoded credential vulnerabilities.

Fortinet Slams Rapid7 For Disclosing Vulnerability

Posted by deepcore under exploit (No Respond)