Subscribe via feed.
Archive for June, 2022

Gentics CMS 5.36.29 Cross Site Scripting / Deserialization

Posted by deepcore under exploit (No Respond)

Gentics CMS version 5.36.29 suffers from persistent cross site scripting and unsafe java deserialization vulnerabilities.

SoftGuard SNMP Network Management Extension HTML Injection / File Download

Posted by deepcore under exploit (No Respond)

SoftGuard Web (SGW) versions prior to 5.1.5 suffer from html injection and arbitrary file system access allow for file downloads.

Mitel 6800/6900 Series SIP Phones Backdoor Access

Posted by deepcore under exploit (No Respond)

Mitel 6800/6900 Series SIP Phones excluding 6970 and Mitel 6900 Series IP (MiNet) Phones have a flow to spawn a telnet backdoor on the device with a static root password enabled. Affected versions include Rel 5.1 SP8 (5.1.0.8016) and earlier, Rel 6.0 (6.0.0.368) to 6.1 HF4 (6.1.0.165), and MiNet 1.8.0.12 and earlier.

Lepin EP-KP001 KP001_V19 Authentication Bypass

Posted by deepcore under exploit (No Respond)

When analyzing the USB flash drive Lepin EP-KP001, Matthias Deeg found out that it uses an insecure hardware design which allows an attacker to bypass the password-based user authentication.

Nexans FTTO GigaSwitch Outdated Components / Hardcoded Backdoor

Posted by deepcore under exploit (No Respond)

Nexans FTTO GigaSwitch industrial/office switches HW version 5 suffer from having a hardcoded backdoor user and multiple outdated vulnerable software components.

SIEMENS-SINEMA Remote Connect 3.0.1.0-01.01.00.02 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SIEMENS-SINEMA Remote Connect versions 3.0.1.0-01.01.00.02 and below suffer from a cross site scripting vulnerability.

SIEMENS-SINEMA Remote Connect 3.0.1.0-01.01.00.02 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SIEMENS-SINEMA Remote Connect versions 3.0.1.0-01.01.00.02 and below suffer from a cross site scripting vulnerability.

http://nonedu2.go.th/kz.html

Posted by deepcore under defacement (No Respond)

http://nonedu2.go.th/kz.html notified by Mr.Kro0oz.305

Tags:

https://sakon2.go.th/daka.htm

Posted by deepcore under defacement (No Respond)

https://sakon2.go.th/daka.htm notified by telegram@saturaa

Tags:

http://www7.djop.go.th/index2.html

Posted by deepcore under defacement (No Respond)

http://www7.djop.go.th/index2.html notified by ALHOSANE

Tags: