Subscribe via feed.
Archive for September, 2021

Cloudron 6.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Cloudron version 6.2 suffers from a cross site scripting vulnerability.

Library Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Library Management System version 1.0 suffers from a remote blind time-based SQL injection vulnerability.

WordPress WooCommerce Booster 5.4.3 Authentication Bypass

Posted by deepcore under exploit (No Respond)

WordPress WooCommerce Booster plugin version 5.4.3 suffers from an authentication bypass vulnerability.

Geutebruck instantrec Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow within the ‘action’ parameter of the /uapi-cgi/instantrec.cgi page of Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions equal to 1.12.0.27 as well as firmware versions 1.12.13.2 and 1.12.14.5. Successful exploitation results in remote code execution as the root user.

Geutebruck instantrec Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow within the ‘action’ parameter of the /uapi-cgi/instantrec.cgi page of Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions equal to 1.12.0.27 as well as firmware versions 1.12.13.2 and 1.12.14.5. Successful exploitation results in remote code execution as the root user.

Impress CMS 1.4.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Impress CMS version 1.4.2 suffers from a remote code execution vulnerability.

Microsoft Windows cmd.exe Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

Microsoft Windows cmd.exe suffers from a stack buffer overflow vulnerability.

Git git-lfs Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit modules exploits a critical vulnerability in Git Large File Storage (Git LFS), an open source Git extension for versioning large files, which allows attackers to achieve remote code execution if the Windows-using victim is tricked into cloning the attacker’s malicious repository using a vulnerable Git version control tool.

Azure Zero Day Flaws Highlight Lurking Supply Chain Risk

Posted by deepcore under exploit (No Respond)

[webapps] Simple Attendance System 1.0 – Authenticated bypass

Posted by deepcore under Security (No Respond)

Simple Attendance System 1.0 – Authenticated bypass

Tags: ,