Subscribe via feed.
Archive for April, 2022

Delta Controls enteliTOUCH 3.40.3935 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Delta Controls enteliTOUCH versions 3.40.3935, 3.40.3706, and 3.33.4005 suffer from a cross site scripting vulnerability.

Delta Controls enteliTOUCH 3.40.3935 Cookie User Password Disclosure

Posted by deepcore under exploit (No Respond)

Delta Controls enteliTOUCH versions 3.40.3935, 3.40.3706, and 3.33.4005 suffer from a cookie user password disclosure vulnerability.

https://www.nsw2.go.th/1975.html

Posted by deepcore under defacement (No Respond)

https://www.nsw2.go.th/1975.html notified by 1975 Team

Tags:

https://nb2.go.th/1975.html

Posted by deepcore under defacement (No Respond)

https://nb2.go.th/1975.html notified by 1975 Team

Tags:

http://www.chon3.go.th/1975.html

Posted by deepcore under defacement (No Respond)

http://www.chon3.go.th/1975.html notified by 1975 Team

Tags:

Delta Controls enteliTOUCH 3.40.3935 Cookie User Password Disclosure

Posted by deepcore under exploit (No Respond)

Delta Controls enteliTOUCH versions 3.40.3935, 3.40.3706, and 3.33.4005 suffer from a cookie user password disclosure vulnerability.

Verizon 4G LTE Network Extender 0.4.038.2131 Weak Credential Algorithm

Posted by deepcore under exploit (No Respond)

Verizon’s 4G LTE Network Extender is utilizing a weak default admin password generation algorithm. The password is generated using the last 4 values from device’s MAC address which is disclosed on the main webUI login page to an unauthenticated attacker. The values are then concatenated with the string LTEFemto resulting in something like LTEFemtoD080 as […]

Spring4Shell Code Execution

Posted by deepcore under exploit (No Respond)

Python exploit for CVE-2022-22965 that provides a prompt to the user in the style of an ssh session. The script is designed to be easy to understand and execute, with both readability and accessibility – depending on the user’s choice. Designed for exploiting the vulnerability on tomcat servers. The fileDateFormat field on the server will […]

Microsoft Zero Days, Wormable Bugs Spark Concern

Posted by deepcore under exploit (No Respond)

Spring4Shell Code Execution

Posted by deepcore under exploit (No Respond)

Python exploit for CVE-2022-22965 that provides a prompt to the user in the style of an ssh session. The script is designed to be easy to understand and execute, with both readability and accessibility – depending on the user’s choice. Designed for exploiting the vulnerability on tomcat servers. The fileDateFormat field on the server will […]