Subscribe via feed.
Archive for January, 2022

Fetch Softworks Fetch FTP Client 5.8 Denial Of Service

Posted by deepcore under exploit (No Respond)

Fetch Softworks Fetch FTP Client version 5.8 suffers from a remote CPU consumption denial of service vulnerability.

WordPress Mortgage Calculators WP 1.52 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Mortgage Calculators WP plugin version 1.52 suffers from a persistent cross site scripting vulnerability.

Oracle WebLogic Server 14.1.1.0.0 Local File Inclusion

Posted by deepcore under exploit (No Respond)

Oracle WebLogic Server suffers from a local file inclusion vulnerability. Versions affected include 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0.

PolicyKit-1 0.105-31 Privilege Escalation

Posted by deepcore under exploit (No Respond)

PolicyKit-1 version 0.105-31 pkexec local privilege escalation exploit.

WordPress Modern Events Calendar 6.1 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress Modern Events Calendar plugin versions 6.1 and below suffer from an unauthenticated remote SQL injection vulnerability.

WordPress RegistrationMagic V 5.0.1.5 SQL Injection

Posted by deepcore under exploit (No Respond)

WordPress RegistrationMagic V plugin versions 5.0.1.5 and below suffer from a remote SQL injection vulnerability.

Apple Fixes 2 Zero-Day Security Bugs, One Exploited In the Wild

Posted by deepcore under exploit (No Respond)

Polkit pkexec CVE-2021-4034 Local Root

Posted by deepcore under exploit (No Respond)

Local privilege escalation root exploit for Polkit’s pkexec vulnerability as described in CVE-2021-4034 and known as PwnKit.

Backdoor.Win32.WinShell.50 Weak Hardcoded Password

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.WinShell.50 malware suffers from a weak hardcoded password vulnerability.

Polkit pkexec CVE-2021-4034 Proof Of Concept

Posted by deepcore under exploit (No Respond)

Local privilege escalation root exploit for Polkit’s pkexec vulnerability as described in CVE-2021-4034. Verified on Debian 10 and CentOS 7. Written in C.