Subscribe via feed.
Archive for July, 2022

Windows LSA Service LsapGetClientInfo Impersonation Level Check Privilege Escalation

Posted by deepcore under exploit (No Respond)

On Microsoft Windows, the LsapGetClientInfo API in LSASRV will fallback and directly capture a caller’s impersonation token if it fails to impersonate, leading to elevation of privilege if the impersonation level is not checked.

Windows Kernel nt!MiRelocateImage Invalid Read

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from an invalid read in nt!MiRelocateImage while parsing a malformed PE file.

http://www.bankangcity.go.th/index.php

Posted by deepcore under defacement (No Respond)

http://www.bankangcity.go.th/index.php notified by ./Niz4r

Tags:

http://www.tungsawang.go.th/index.php

Posted by deepcore under defacement (No Respond)

http://www.tungsawang.go.th/index.php notified by ./Niz4r

Tags:

Windows Kernel nt!MiRelocateImage Invalid Read

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from an invalid read in nt!MiRelocateImage while parsing a malformed PE file.

PrestaShop 1.7.6.7 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PrestaShop version 1.7.6.7 suffers from a cross site scripting vulnerability via the file upload functionality.

PrestaShop 1.7.6.7 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

PrestaShop version 1.7.6.7 suffers from a cross site scripting vulnerability via the file upload functionality.

Sourcegraph gitserver sshCommand Remote Command Execution

Posted by deepcore under exploit (No Respond)

A vulnerability exists within Sourcegraph’s gitserver component that allows a remote attacker to execute arbitrary OS commands by modifying the core.sshCommand value within the git configuration. This command can then be triggered on demand by executing a git push operation. The vulnerability was patched by introducing a feature flag in version 3.37.0. This flag must […]

Sourcegraph gitserver sshCommand Remote Command Execution

Posted by deepcore under exploit (No Respond)

A vulnerability exists within Sourcegraph’s gitserver component that allows a remote attacker to execute arbitrary OS commands by modifying the core.sshCommand value within the git configuration. This command can then be triggered on demand by executing a git push operation. The vulnerability was patched by introducing a feature flag in version 3.37.0. This flag must […]

http://amss.ses26.go.th

Posted by deepcore under defacement (No Respond)

http://amss.ses26.go.th notified by XnonGermx

Tags: