Subscribe via feed.
Archive for October, 2021

Netgear Genie 2.4.64 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Netgear Genie version 2.4.64 suffers from an unquoted service path vulnerability.

Balbooa Joomla Forms Builder 2.0.6 SQL Injection

Posted by deepcore under exploit (No Respond)

Balbooa Joomla Forms Builder version 2.0.6 suffers from a remote SQL injection vulnerability.

OpenClinic GA 5.194.18 Privilege Escalation

Posted by deepcore under exploit (No Respond)

OpenClinic GA version 5.194.18 suffers from a local privilege escalation vulnerability.

Online Event Booking And Reservation System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Event Booking and Reservation System version 1.0 suffers from a persistent cross site scripting vulnerability.

Engineers Online Portal 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Engineers Online Portal version 1.0 suffers from a persistent cross site scripting vulnerability.

Engineers Online Portal 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Engineers Online Portal version 1.0 suffers from multiple remote SQL injection vulnerabilities. Original discovery of SQL injection in this version is attributed to n11secur1ty in October of 2021.

GridPro Request Management For Windows Azure Pack 2.0.7905 Directory Traversal

Posted by deepcore under exploit (No Respond)

GridPro Request Management for Windows Azure Pack versions 2.0.7905 and below suffer from a traversal vulnerability that can allow for arbitrary execution of Powershell scripts.

FreeSWITCH 1.10.6 SIP Digest Leak

Posted by deepcore under exploit (No Respond)

FreeSWITCH versions 1.10.6 and below suffer from a SIP digest leak vulnerability. An attacker can perform a SIP digest leak attack against FreeSWITCH and receive the challenge response of a gateway configured on the FreeSWITCH server. This is done by challenging FreeSWITCH’s SIP requests with the realm set to that of the gateway, thus forcing […]

phpMyAdmin 4.8.1 Remote Code Execution

Posted by deepcore under exploit (No Respond)

phpMyAdmin version 4.8.1 remote code execution exploit.

FreeSWITCH 1.10.6 SIP Flooding Denial Of Service

Posted by deepcore under exploit (No Respond)

FreeSWITCH versions 1.10.6 and below suffer from a SIP flooding denial of service vulnerability.