Subscribe via feed.
Archive for May, 2022

Zoom XMPP Stanza Smuggling Remote Code Execution

Posted by deepcore under exploit (No Respond)

This report describes a vulnerability chain that enables a malicious user to compromise another user over Zoom chat. User interaction is not required for a successful attack. The only ability an attacker needs is to be able to send messages to the victim over Zoom chat over XMPP protocol. Initial vulnerability (labeled XMPP Stanza Smuggling) […]

CLink Office 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

CLink Office version 2.0 anti-spam management console suffers from a remote SQL injection vulnerability.

Online Fire Reporting System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Fire Reporting System version 1.0 suffers from a remote SQL injection vulnerability.

Online Fire Reporting System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Fire Reporting System version 1.0 suffers from a remote SQL injection vulnerability.

[webapps] qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)

Posted by deepcore under Security (No Respond)

qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)

Tags: ,

OpenCart Newsletter 3.0.2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

OpenCart Newsletter module version 3.0.2.0 suffers from a remote blind SQL injection vulnerability.

Blockchain AltExchanger 1.2.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Blockchain AltExchanger version 1.2.1 suffers from multiple remote SQL injection vulnerabilities.

Blockchain FiatExchanger 2.2.1 SQL Injection

Posted by deepcore under exploit (No Respond)

Blockchain FiatExchanger version 2.2.1 suffers from a remote blind SQL injection vulnerability.

m1k1o's Blog 1.3 Remote Code Execution

Posted by deepcore under exploit (No Respond)

m1k1o’s Blog versions 1.3 and below suffer from an authenticated remote code execution vulnerability.

iTop Remote Command Execution

Posted by deepcore under exploit (No Respond)

iTop versions prior to 2.7.5 authenticated remote command execution exploit.