Subscribe via feed.
Archive for January, 2022

Online Diagnostic Lab Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Diagnostic Lab Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Online Diagnostic Lab Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Diagnostic Lab Management System version 1.0 suffers from a remote SQL injection vulnerability.

WordPress Frontend Uploader 1.3.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Frontend Uploader plugin version 1.3.2 suffers from a persistent cross site scripting vulnerability.

Libstagefright Heap Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

Libstagefright, the media framework on Android, suffers from an out-of-bounds write vulnerability on the heap.

Crestron HD-MD4X2-4K-E 1.0.0.2159 Credential Disclosure

Posted by deepcore under exploit (No Respond)

Crestron HD-MD4X2-4K-E version 1.0.0.2159 suffers from a credential disclosure vulnerability. When the administrative web interface of the Crestron HDMI switcher is accessed unauthenticated, user credentials are disclosed which are valid to authenticate to the web interface.

Log4Shell HTTP Header Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module will exploit an HTTP end point with the Log4Shell vulnerability by injecting a format message that will trigger an LDAP connection to Metasploit and load a payload. The Automatic target delivers a Java payload using remote class loading. This requires Metasploit to run an HTTP server in addition to the LDAP server […]

Microsoft Starts 2022 With Big Bundle Fixes For 96 Security Bugs In Its Software

Posted by deepcore under exploit (No Respond)

[webapps] WordPress Core 5.8.2 – 'WP_Query' SQL Injection

Posted by deepcore under Security (No Respond)

WordPress Core 5.8.2 – ‘WP_Query’ SQL Injection

Tags: ,

[webapps] Online Diagnostic Lab Management System 1.0 – Stored Cross Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

Online Diagnostic Lab Management System 1.0 – Stored Cross Site Scripting (XSS)

Tags: ,

[webapps] Online Diagnostic Lab Management System 1.0 – Account Takeover (Unauthenticated)

Posted by deepcore under Security (No Respond)

Online Diagnostic Lab Management System 1.0 – Account Takeover (Unauthenticated)

Tags: ,