Subscribe via feed.
Archive for September, 2021

Backdoor.Win32.MoonPie.40 Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.MoonPie.40 malware suffers from a man-in-the-middle vulnerability.

Compro Technology IP Camera RTSP Stream Disclosure

Posted by deepcore under exploit (No Respond)

Compro Technology IP Camera suffers from an unauthenticated RTSP stream disclosure vulnerability.

Compro Technology IP Camera Credential Disclosure

Posted by deepcore under exploit (No Respond)

Compro Technology IP Camera suffers from multiple credential disclosure vulnerabilities.

Dolibarr ERP/CRM 14.0.1 Privilege Escalation

Posted by deepcore under exploit (No Respond)

Dolibarr ERP/CRM versions 14.0.1 and below suffer from a privilege escalation vulnerability.

Backdoor.Win32.MoonPie.40 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.MoonPie.40 malware suffers from an unauthenticated remote command execution vulnerability.

Compro Technology IP Camera Stream Disclosure

Posted by deepcore under exploit (No Respond)

Compro Technology IP Camera suffers from a stream disclosure vulnerability.

Compro Technology IP Camera Screenshot Disclosure

Posted by deepcore under exploit (No Respond)

Compro Technology IP Camera suffers from a screenshot disclosure vulnerability.

CyberArk Credential Provider Race Condition / Authorization Bypass

Posted by deepcore under exploit (No Respond)

CyberArk’s Credential Provider loopback communications on TCP port 18923 are encrypted with key material that has extremely low entropy. In all currently-known use cases, the effective key space is less than 2^16. For an attacker who understands the key derivation scheme and encryption mechanics, knowledge of the source port and access to the payloads of […]

Geutebruck Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module bypasses the HTTP basic authentication used to access the /uapi-cgi/ folder and exploits multiple authenticated arbitrary command execution vulnerabilities within the parameters of various pages on Geutebruck G-Cam EEC-2xxx and G-Code EBC-21xx, EFD-22xx, ETHC-22xx, and EWPC-22xx devices running firmware versions 1.12.0.27 and below as well as firmware versions 1.12.13.2 and 1.12.14.5. Successful […]

[webapps] OpenSIS 8.0 'modname' – Directory/Path Traversal

Posted by deepcore under Security (No Respond)

OpenSIS 8.0 ‘modname’ – Directory/Path Traversal

Tags: ,