Subscribe via feed.
Archive for September, 2021

Church Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Church Management System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to Murat Demirci in July of 2021.

T-Soft E-Commerce 4 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

T-Soft E-Commerce version 4 suffers from a cross site request forgery vulnerability.

Microsoft Windows MSHTML Overview

Posted by deepcore under exploit (No Respond)

This article discusses the CVE-2021-40444 vulnerability and an alternative path that reduces the lines of JS code to trigger the issue and does not require CAB archives.

Apple Security Advisory 2021-09-13-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-09-13-1 – iOS 14.8 and iPadOS 14.8 addresses code execution, integer overflow, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-09-13-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-09-13-2 – watchOS 7.6.2 addresses code execution and integer overflow vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-09-13-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-09-13-3 – macOS Big Sur 11.6 addresses code execution, integer overflow, and use-after-free vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-09-13-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-09-13-4 – Security Update 2021-005 Catalina addresses code execution and integer overflow vulnerabilities.

Tags: , ,

Apple Security Advisory 2021-09-13-5

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2021-09-13-5 – Safari 14.1.2 addresses code execution and use-after-free vulnerabilities.

Tags: , ,

[dos] Yenkee Hornet Gaming Mouse – 'GM312Fltr.sys' Denial-Of-Service (PoC)

Posted by deepcore under Security (No Respond)

Yenkee Hornet Gaming Mouse – ‘GM312Fltr.sys’ Denial-Of-Service (PoC)

Tags: ,

[webapps] WebsiteBaker 2.13.0 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

WebsiteBaker 2.13.0 – Remote Code Execution (RCE) (Authenticated)

Tags: ,