Subscribe via feed.
Archive for January, 2022

CollectorStealerBuilder Panel 2.0.0 Insecure Credential Storage

Posted by deepcore under exploit (No Respond)

The panel for Collector Stealer malware version 2.0.0 stores the login credentials in plaintext in its MySQL database. Third-party attackers who gain access to the system can read the database username passwords without having to crack them offline.

CollectorStealerBuilder Panel 2.0.0 Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

The panel for Collector Stealer malware version 2.0.0 suffers from a man-in-the-middle vulnerability.

Backdoor.Win32.Wisell Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Wisell malware suffers from a remote command execution vulnerability.

Ransomware Builder Babuk Insecure Permissions

Posted by deepcore under exploit (No Respond)

Ransomware Builder Babuk malware suffers from an insecure permissions vulnerability.

VMware vCenter Server Unauthenticated Log4Shell JNDI Injection Remote Code Execution

Posted by deepcore under exploit (No Respond)

VMware vCenter Server is affected by the Log4Shell vulnerability whereby a JNDI string can be sent to the server that will cause it to connect to the attacker and deserialize a malicious Java object. This results in OS command execution in the context of the root user in the case of the Linux virtual appliance […]

Grandstream GXV3175 Unauthenticated Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in Grandstream GXV3175 IP multimedia phones. The settimezone action does not validate input in the timezone parameter allowing injection of arbitrary commands. A buffer overflow in the phonecookie cookie parsing allows authentication to be bypassed by providing an alphanumeric cookie 93 characters in length. This module was […]

WordPress Email Template Designer – WP HTML Mail 3.0.9 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Email Template Designer – WP HTML Mail plugin versions 3.0.9 and below suffer from a cross site scripting vulnerability.

Nyron 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Nyron version 1.0 suffers from a remote SQL injection vulnerability.

Simple Chatbot Application 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Simple Chatbot Application version 1.0 suffers from a remote blind SQL injection vulnerability.

Simple Chatbot Application 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Simple Chatbot Application version 1.0 suffers from a remote shell upload vulnerability.