Subscribe via feed.
Archive for June, 2022

Kik Messenger XMPP Stanza Smuggling

Posted by deepcore under exploit (No Respond)

There is a vulnerability in Kik Messenger for Android that allows an attacker to send arbitrary XMPP stanzas (XMPP control messages) to another Kik client, including XMPP stanzas that are normally sent only by the Kik server. Included is a proof of concept that demonstrates sending of the stc stanza which triggers a captcha dialog […]

https://wangsomboonhospital.go.th/1975.html

Posted by deepcore under defacement (No Respond)

https://wangsomboonhospital.go.th/1975.html notified by 1975 Team

Tags:

Kik Messenger XMPP Stanza Smuggling

Posted by deepcore under exploit (No Respond)

There is a vulnerability in Kik Messenger for Android that allows an attacker to send arbitrary XMPP stanzas (XMPP control messages) to another Kik client, including XMPP stanzas that are normally sent only by the Kik server. Included is a proof of concept that demonstrates sending of the stc stanza which triggers a captcha dialog […]

https://khamthoa.go.th/kz.html

Posted by deepcore under defacement (No Respond)

https://khamthoa.go.th/kz.html notified by Mr.Kro0oz.305

Tags:

https://sikhiotown.go.th/kz.html

Posted by deepcore under defacement (No Respond)

https://sikhiotown.go.th/kz.html notified by Mr.Kro0oz.305

Tags:

[webapps] Confluence Data Center 7.18.0 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

Confluence Data Center 7.18.0 – Remote Code Execution (RCE)

Tags: ,

[webapps] WordPress Plugin Motopress Hotel Booking Lite 4.2.4 – Stored Cross-Site Scripting (XSS)

Posted by deepcore under Security (No Respond)

WordPress Plugin Motopress Hotel Booking Lite 4.2.4 – Stored Cross-Site Scripting (XSS)

Tags: ,

WordPress Download Manager 3.2.42 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Download Manager versions 3.2.42 and below suffer from a cross site scripting vulnerability.

Atlassian Confluence Namespace OGNL Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an OGNL injection in Atlassian Confluence servers. A specially crafted URI can be used to evaluate an OGNL expression resulting in OS command execution.

Atlassian Confluence Namespace OGNL Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an OGNL injection in Atlassian Confluence servers. A specially crafted URI can be used to evaluate an OGNL expression resulting in OS command execution.