Subscribe via feed.
Archive for January, 2022

Polkit pkexec CVE-2021-4034 Local Root

Posted by deepcore under exploit (No Respond)

Local privilege escalation root exploit for Polkit’s pkexec vulnerability as described in CVE-2021-4034 and known as PwnKit. Written in Go.

Linux Kernel Slab Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

Local privilege escalation exploit for a Linux kernel slab out-of-bounds write vulnerability. This exploit has been tested in an Ubuntu 21.04 Hirsute with kernel 5.11.0.

Linux Kernel Slab Out-Of-Bounds Write

Posted by deepcore under exploit (No Respond)

This archive contains demo exploits for CVE-2022-0185. There are two versions here. The non-kctf version (fuse version) specifically targets Ubuntu with kernel version 5.11.0-44. It does not directly return a root shell, but makes /bin/bash suid, which will lead to trivial privilege escalation. Adjusting the single_start and modprobe_path offsets should allow it to work on […]

[remote] Oracle WebLogic Server 14.1.1.0.0 – Local File Inclusion

Posted by deepcore under Security (No Respond)

Oracle WebLogic Server 14.1.1.0.0 – Local File Inclusion

Tags: ,

[webapps] WordPress Plugin Modern Events Calendar V 6.1 – SQL Injection (Unauthenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin Modern Events Calendar V 6.1 – SQL Injection (Unauthenticated)

Tags: ,

[webapps] WordPress Plugin RegistrationMagic V 5.0.1.5 – SQL Injection (Authenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin RegistrationMagic V 5.0.1.5 – SQL Injection (Authenticated)

Tags: ,

[webapps] WordPress Plugin Mortgage Calculators WP 1.52 – Stored Cross-Site Scripting (XSS) (Authenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin Mortgage Calculators WP 1.52 – Stored Cross-Site Scripting (XSS) (Authenticated)

Tags: ,

TYPO3 femanager 6.3.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

TYPO3 femanager extension versions 6.0.0 through 6.0.3 and 5.5.0 and below suffer from a persistent cross site scripting vulnerability.

H2 Database Console Remote Code Execution

Posted by deepcore under exploit (No Respond)

The H2 Database console suffers from an unauthenticated remote code execution vulnerability.

Online Project Time Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Project Time Management System version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.