Subscribe via feed.
Archive for September, 2022

Windows Credential Guard TGT Renewal Information Disclosure

Posted by deepcore under exploit (No Respond)

On Windows, the Kerberos ticket renewal process can be used with CG to get an unencrypted TGT session key for a currently authenticated user leading to information disclosure.

.NET XML Signature Verification External Entity Injection

Posted by deepcore under exploit (No Respond)

XML signature verification in .NET 6 as implemented in System.Security.Cryptography.Xml.SignedXml is vulnerable to external entity injection attacks.

Sagemath 9.0 Overflow / Denial Of Service

Posted by deepcore under exploit (No Respond)

Sagemath version 9.0 suffers from overflow and denial of service vulnerabilities.

http://amss.ayutthaya2.go.th/read.html

Posted by deepcore under defacement (No Respond)

http://amss.ayutthaya2.go.th/read.html notified by ./Niz4r

Tags:

http://salary.ayutthaya2.go.th/read.html

Posted by deepcore under defacement (No Respond)

http://salary.ayutthaya2.go.th/read.html notified by ./Niz4r

Tags:

http://sawat.ayutthaya2.go.th/read.html

Posted by deepcore under defacement (No Respond)

http://sawat.ayutthaya2.go.th/read.html notified by ./Niz4r

Tags:

http://smss.ayutthaya2.go.th/read.html

Posted by deepcore under defacement (No Respond)

http://smss.ayutthaya2.go.th/read.html notified by ./Niz4r

Tags:

Apache Spark Unauthenticated Command Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated command injection vulnerability in Apache Spark. Successful exploitation results in remote code execution under the context of the Spark application user. The command injection occurs because Spark checks the group membership of the user passed in the ?doAs parameter by using a raw Linux command. It is triggered by […]

Trojan.Win32.Autoit.fhj MVID-2022-0637 Insecure Permissions

Posted by deepcore under exploit (No Respond)

Trojan.Win32.Autoit.fhj malware suffers from an insecure permissions vulnerability.

FTPManager 8.2 Local File Inclusion / Directory Traversal

Posted by deepcore under exploit (No Respond)

FTPManager version 8.2 suffers from local file inclusion and directory traversal vulnerabilities.