Subscribe via feed.
Archive for September, 2022

Netfilter nft_set_elem_init Heap Overflow Privilege Escalation

Posted by deepcore under exploit (No Respond)

An issue was discovered in the Linux kernel through version 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges. The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access. The issue exists in nft_setelem_parse_data […]

Mobile Mouse Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module utilizes the Mobile Mouse Server by RPA Technologies, Inc protocol to deploy a payload and run it from the server. This module will only deploy a payload if the server is set without a password (default). Tested against 3.6.0.4, the current version at the time of module writing.

http://pbns.go.th/robots.txt

Posted by deepcore under defacement (No Respond)

http://pbns.go.th/robots.txt notified by Typical Idiot Security

Tags:

http://www.spin.dss.go.th/bas/public/site/images/admin1/mwhehe.gif

Posted by deepcore under defacement (No Respond)

http://www.spin.dss.go.th/bas/public/site/images/admin1/mwhehe.gif notified by Simsimi

Tags:

Food Ordering Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Food Ordering Management System version 1.0 suffers from a remote SQL injection vulnerability.

Online Birth Certificate Management System 1.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Online Birth Certificate Management System version 1.0 suffers from a cross site request forgery vulnerability.

Online Birth Certificate Management System 1.0 Insecure Direct Object Reference

Posted by deepcore under exploit (No Respond)

Online Birth Certificate Management System version 1.0 suffers from an insecure direct object reference vulnerability.

Online Birth Certificate Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Birth Certificate Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Online Birth Certificate Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Online Birth Certificate Management System version 1.0 suffers from a cross site scripting vulnerability.

COVESA 2.18.8 NULL Pointer Dereference / Heap Buffer Over-Read

Posted by deepcore under exploit (No Respond)

COVESA versions 2.18.8 and below suffer from heap buffer over-read and null pointer dereference vulnerabilities.