Subscribe via feed.
Archive for December, 2021

Chikitsa Patient Management System 2.0.2 Backup Remote Code Execution

Posted by deepcore under exploit (No Respond)

Chikitsa Patient Management System version 2.0.2 suffers from a backup related authenticated remote code execution vulnerability.

Chikitsa Patient Management System 2.0.2 Plugin Remote Code Execution

Posted by deepcore under exploit (No Respond)

Chikitsa Patient Management System version 2.0.2 suffers from a plugin related authenticated remote code execution vulnerability.

MTPutty 1.0.1.21 SSH Password Disclosure

Posted by deepcore under exploit (No Respond)

MTPutty version 1.0.1 suffers from an SSH password disclosure vulnerability.

WordPress Catch Themes Demo Import 1.6.1 Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress Catch Themes Demo Import plugin versions 1.6.1 and below suffer from a remote shell upload vulnerability.

TestLink 1.19 Arbitrary File Download

Posted by deepcore under exploit (No Respond)

TestLink versions 1.16 through 1.19 suffer from an arbitrary file download vulnerability.

LimeSurvey 5.2.4 Remote Code Execution

Posted by deepcore under exploit (No Respond)

LimeSurvey version 5.2.4 remote code execution exploit with a reverse shell.

Microsoft Office Word MSHTML Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module creates a malicious docx file that when opened in Word on a vulnerable Windows system will lead to code execution. This vulnerability exists because an attacker can craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine.

Grafana 8.3.0 Directory Traversal / Arbitrary File Read

Posted by deepcore under exploit (No Respond)

Grafana version 8.3.0 suffers from a directory traversal vulnerability that can allow for arbitrary file reading.

[webapps] OpenCATS 0.9.4 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

OpenCATS 0.9.4 – Remote Code Execution (RCE)

Tags: ,

Docker runc Command Execution Proof Of Concept

Posted by deepcore under exploit (No Respond)

Docker proof of concept command execution exploit that leverages runc.