Subscribe via feed.
Archive for January, 2022

Backdoor.Win32.DRA.c Weak Hardcoded Password

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.DRA.c malware suffers from a weak hardcoded password vulnerability.

CosaNostra Builder Insecure Permissions

Posted by deepcore under exploit (No Respond)

CosaNostra Builder malware suffers from an insecure permissions vulnerability.

Xerox Versalink Denial Of Service

Posted by deepcore under exploit (No Respond)

Xerox Versalink printers suffer from a remote denial of service vulnerability using a specially crafted TIFF payload.

CosaNostra Builder WebPanel Insecure Cryptographic Storage

Posted by deepcore under exploit (No Respond)

CosaNostra Builder WebPanel malware only uses straight MD5 to store passwords without any salt.

FAUST iServer 9.0.018.018.4 Local File Inclusion

Posted by deepcore under exploit (No Respond)

Land Software’s FAUST iServer versions 9.0.017.017.1-3 through 9.0.018.018.4 suffer from a local file inclusion vulnerability.

uBidAuction 2.0.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

uBidAuction version 2.0.1 suffers from a cross site scripting vulnerability.

CosaNostra Builder WebPanel Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

CosaNostra Builder WebPanel malware suffers from a cross site request forgery vulnerability.

Ethercreative Logs 3.0.3 Path Traversal

Posted by deepcore under exploit (No Respond)

Ethercreative Logs plugin versions 3.0.3 and below for Craft CMS suffer from a path traversal vulnerability.

Grandstream UCM62xx IP PBX sendPasswordEmail Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated SQL injection vulnerability and a command injection vulnerability affecting the Grandstream UCM62xx IP PBX series of devices. The vulnerabilities allow an unauthenticated remote attacker to execute commands as root.

XNU Kernel mach_msg Use-After-Free

Posted by deepcore under exploit (No Respond)

The XNU kernel suffers from a use-after-free vulnerability in mach_msg.