Subscribe via feed.
Archive for February, 2022

Backdoor.Win32.XRat.k Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.XRat.k malware suffers from an unauthenticated remote command execution vulnerability.

Exam Reviewer Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Exam Reviewer Management System version 1.0 suffers from a remote SQL injection vulnerability.

Exam Reviewer Management System 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Exam Reviewer Management System version 1.0 suffers from a remote shell upload vulnerability.

Backdoor.Win32.Prexot.a Man-In-The-Middle

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Prexot.a malware suffers from a man-in-the-middle vulnerability.

Backdoor.Win32.Wdoor.11 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Wdoor.11 malware suffers from an unauthenticated remote command execution vulnerability.

Atom CMS 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Atom CMS version 2.0 suffers from a remote SQL injection vulnerability.

Backdoor.Win32.Prexot.a Authentication Bypass

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Prexot.a malware suffers from a bypass vulnerability.

Backdoor.Win32.Freddy.2001 Authentication Bypass / Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Freddy.2001 malware suffers from authentication bypass and remote command execution vulnerabilities.

Grandstream GXV31XX settimezone Unauthenticated Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability in Grandstream GXV31XX IP multimedia phones. The settimezone action does not validate input in the timezone parameter allowing injection of arbitrary commands. A buffer overflow in the phonecookie cookie parsing allows authentication to be bypassed by providing an alphanumeric cookie 93 characters in length. This module was […]

[webapps] WordPress Plugin Jetpack 9.1 – Cross Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

WordPress Plugin Jetpack 9.1 – Cross Site Scripting (XSS)

Tags: ,