Subscribe via feed.
Archive for May, 2022

Chrome 100 extensions::ExtensionApiFrameIdMap::GetFrameId Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

A use-after-free issue exists in Chrome 100 and earlier versions. A malicious extension can achieve arbitrary code execution in the browser process.

Zyxel Firewall ZTP Unauthenticated Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits CVE-2022-30525, an unauthenticated remote command injection vulnerability affecting Zyxel firewalls with zero touch provisioning (ZTP) support. By sending a malicious setWanPortSt command containing an mtu field with a crafted OS command to the /ztp/cgi-bin/handler page, an attacker can gain remote command execution as the nobody user. Affected Zyxel models are USG […]

[webapps] Showdoc 2.10.3 – Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

Showdoc 2.10.3 – Stored Cross-Site Scripting (XSS)

Tags: ,

[remote] SolarView Compact 6.0 – OS Command Injection

Posted by deepcore under Security (No Respond)

SolarView Compact 6.0 – OS Command Injection

Tags: ,

[webapps] T-Soft E-Commerce 4 – SQLi (Authenticated)

Posted by deepcore under Security (No Respond)

T-Soft E-Commerce 4 – SQLi (Authenticated)

Tags: ,

[remote] SDT-CW3B1 1.1.0 – OS Command Injection

Posted by deepcore under Security (No Respond)

SDT-CW3B1 1.1.0 – OS Command Injection

Tags: ,

[webapps] T-Soft E-Commerce 4 – 'UrunAdi' Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

T-Soft E-Commerce 4 – ‘UrunAdi’ Stored Cross-Site Scripting (XSS)

Tags: ,

[webapps] Survey Sparrow Enterprise Survey Software 2022 – Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

Survey Sparrow Enterprise Survey Software 2022 – Stored Cross-Site Scripting (XSS)

Tags: ,

Zyxel Firewall ZTP Unauthenticated Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits CVE-2022-30525, an unauthenticated remote command injection vulnerability affecting Zyxel firewalls with zero touch provisioning (ZTP) support. By sending a malicious setWanPortSt command containing an mtu field with a crafted OS command to the /ztp/cgi-bin/handler page, an attacker can gain remote command execution as the nobody user. Affected Zyxel models are USG […]

Konica Minolta bizhub MFP Printer Terminal Sandbox Escape

Posted by deepcore under exploit (No Respond)

Multiple Konica Minolta bizhub MFP printer terminals suffer from a sandbox escape with root access and have clear-text password vulnerabilities.