Subscribe via feed.
Archive for March, 2022

[webapps] Xerte 3.9 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

Xerte 3.9 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

[webapps] Xerte 3.10.3 – Directory Traversal (Authenticated)

Posted by deepcore under Security (No Respond)

Xerte 3.10.3 – Directory Traversal (Authenticated)

Tags: ,

Cobian Reflector 0.9.93 RC1 Denial Of Service

Posted by deepcore under exploit (No Respond)

Cobian Reflector version 0.9.93 RC1 suffers from a denial of service vulnerability.

Cobian Backup 11 Gravity 11.2.0.582 Denial Of Service

Posted by deepcore under exploit (No Respond)

Cobian Backup 11 Gravity version 11.2.0.582 suffers from a denial of service vulnerability.

Cobian Backup Gravity 11.2.0.582 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Cobian Backup Gravity version 11.2.0.582 suffers from an unquoted service path vulnerability.

WAGO 750-8212 PFC200 G2 2ETH RS Privilege Escalation

Posted by deepcore under exploit (No Respond)

WAGO 750-8212 PFC200 G2 2ETH RS suffers from a privilege escalation vulnerability.

Cipi Control Panel 3.1.15 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Cipi Control Panel version 3.1.15 suffers from a cross site scripting vulnerability.

Casdoor 1.13.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Casdoor version 1.13.0 suffers from a remote SQL injection vulnerability.

Hikvision IP Camera Unauthenticated Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated command injection in a variety of Hikvision IP cameras (CVE-2021-36260). The module inserts a command into an XML payload used with an HTTP PUT request sent to the /SDK/webLanguage endpoint, resulting in command execution as the root user. This module specifically attempts to exploit the blind variant of the […]

Axis IP Camera Shell Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits the “Apps” feature in Axis IP cameras. The feature allows third party developers to upload and execute eap applications on the device. The system does not validate the application comes from a trusted source, so a malicious attacker can upload and execute arbitrary code. The issue has no CVE, although the […]