Subscribe via feed.
Archive for December, 2021

DuckDuckGo 7.64.4 Address Bar Spoofing

Posted by deepcore under exploit (No Respond)

DuckDuckGo version 7.64.4 suffers from an address bar spoofing vulnerability.

Trojan.Win32.Mucc.ivk Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Mucc.ivk malware suffers from an unquoted service path vulnerability.

Online Pre-Owned / Used Car Showroom Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Pre-Owned / Used Car Showroom Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

M-Files Web Denial Of Service

Posted by deepcore under exploit (No Respond)

M-Files Web versions prior to 20.10.9524.1 and M-Files Web versions prior to 20.10.9445.0 contain an improper range header processing vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges (via HTTP requests with a specially-crafted Range or Request-Range headers) to cause the web application to compress each of the requested bytes, resulting in […]

Backdoor.Win32.Vernet.axt Insecure Permissions

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Vernet.axt malware suffers from an insecure permissions vulnerability.

Backdoor.Win32.Bionet.10 Authentication Bypass / Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Bionet.10 malware suffers from bypass and code execution vulnerabilities.

Online Magazine Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Magazine Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

WordPress DZS Zoomsounds 6.45 Arbitrary File Read

Posted by deepcore under exploit (No Respond)

WordPress DZS Zoomsounds plugin version 6.45 suffers from an unauthenticated arbitrary file read vulnerability.

Backdoor.Win32.WinShell.50 Hardcoded Password

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.WinShell.50 malware suffers from a hard-coded password vulnerability.

WordPress Slider By Soliloquy 2.6.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Slider By Soliloquy plugin version 2.6.2 suffers from a persistent cross site scripting vulnerability.