Subscribe via feed.
Archive for August, 2022

PrestaShop Ap Pagebuilder 2.4.4 SQL Injection

Posted by deepcore under exploit (No Respond)

PrestaShop Ap Pagebuilder module versions 2.4.4 and below suffer from a remote SQL injection vulnerability.

Centreon 22.04.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Centreon version 22.04.0 suffers from a persistent cross site scripting vulnerability.

Zimbra Zip Path Traversal

Posted by deepcore under exploit (No Respond)

This Metasploit module POSTs a ZIP file containing path traversal characters to the administrator interface for Zimbra Collaboration Suite. If successful, it plants a JSP-based backdoor within the web directory, then executes it. The core vulnerability is a path traversal issue in Zimbra Collaboration Suite’s ZIP implementation that can result in the extraction of an […]

10-Strike Network Inventory Explorer 9.3 Buffer Overflow

Posted by deepcore under exploit (No Respond)

10-Strike Network Inventory Explorer versions 9.3 and below are vulnerable to a SEH based buffer overflow which leads to code execution or local privilege escalation. The vulnerable part of the program is the functionality to add computers from a text file.

WordPress Duplicator 1.4.7.2 Backup Disclosure

Posted by deepcore under exploit (No Respond)

WordPress Duplicator plugin version 1.4.7.2 suffers from a backup disclosure vulnerability.

Teleport 9.3.6 Command Injection

Posted by deepcore under exploit (No Respond)

Teleport 9.3.6 is vulnerable to command injection leading to remote code execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. […]

http://www.wangdaeng.go.th/capcha/read.html

Posted by deepcore under defacement (No Respond)

http://www.wangdaeng.go.th/capcha/read.html notified by ./Niz4r

Tags:

AppleAVD AVC_RBSP::parseSliceHeader ref_pic_list_modification Overflow

Posted by deepcore under exploit (No Respond)

There is a buffer overflow in how AppleAVD.kext parses the ref_pic_list_modification component of H264 slice headers in AVC_RBSP::parseSliceHeader. When pic modification entries are copied into the pic modification list, the loop only terminates when the end code (3) is encountered, meaning that any number of entries can be copied into the fixed size modification buffer. […]

Personnel Property Equipment 2015-2022 SQL Injection

Posted by deepcore under exploit (No Respond)

Personnel Property Equipment 2015-2022 suffers from a remote SQL injection vulnerability.

Microsoft Exchange Server ChainedSerializationBinder Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits vulnerabilities within the ChainedSerializationBinder as used in Exchange Server 2019 CU10, Exchange Server 2019 CU11, Exchange Server 2016 CU21, and Exchange Server 2016 CU22 all prior to Mar22SU. Note that authentication is required to exploit these vulnerabilities.