Subscribe via feed.
Archive for March, 2022

Backdoor.Win32.BluanWeb Information Disclosure

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.BluanWeb malware suffers from an information leakage vulnerability.

Backdoor.Win32.BluanWeb Remote Code Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.BluanWeb malware suffers from an unauthenticated remote code execution vulnerability.

Backdoor.Win32.BluanWeb Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.BluanWeb malware suffers from an unauthenticated remote command execution vulnerability.

pfSense 2.5.2 Shell Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file creation vulnerability in the pfSense HTTP interface (CVE-2021-41282). The vulnerability affects versions 2.5.2 and below and can be exploited by an authenticated user if they have the “WebCfg – Diagnostics: Routing tables” privilege. This module uses the vulnerability to create a web shell and execute payloads with root […]

Backdoor.Win32.RemoteNC.beta4 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.RemoteNC.beta4 malware suffers from an unauthenticated remote command execution vulnerability.

Polkit pkexec Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

This is a Metasploit module for the argument processing bug in the polkit pkexec binary. If the binary is provided with no arguments, it will continue to process environment variables as argument variables, but without any security checking. By using the execve call we can specify a null argument list and populate the proper environment […]

Printix Client 1.3.1106.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Printix Client versions 1.3.1106.0 and below suffer from a remote code execution vulnerability.

Xerte 3.10.3 Directory Traversal

Posted by deepcore under exploit (No Respond)

Xerte versions 3.10.3 and below suffer from a directory traversal vulnerability.

Xerte 3.9 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Xerte versions 3.9 and below suffer from a remote code execution vulnerability.

Car Driving School Management 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Car Driving School Management version 1.0 suffers from a remote SQL injection vulnerability.