Subscribe via feed.
Archive for September, 2022

[remote] Mobile Mouse 3.6.0.4 – Remote Code Execution (RCE)

Posted by deepcore under Security (No Respond)

Mobile Mouse 3.6.0.4 – Remote Code Execution (RCE)

Tags: ,

https://www.nongpailom.go.th/index.html

Posted by deepcore under defacement (No Respond)

https://www.nongpailom.go.th/index.html notified by SanggamXploiter

Tags:

http://nonsomboonlocal.go.th

Posted by deepcore under defacement (No Respond)

http://nonsomboonlocal.go.th notified by ./Niz4r

Tags:

https://www.cntpeo.go.th/o.htm

Posted by deepcore under defacement (No Respond)

https://www.cntpeo.go.th/o.htm notified by chinafans

Tags:

Chrome LinkToTextMenuObserver::CompleteWithError Heap Use-After-Free

Posted by deepcore under exploit (No Respond)

A use-after-free issue exists in Chrome 104 and earlier versions. Processing maliciously crafted web content may lead to arbitrary code execution in the browser process. LinkToTextMenuObserver holds a raw pointer to a RenderFrameHost object, but is not owned by the frame host and does not watch for frame host destruction events. Therefore, if an attacker […]

Rocket LMS 1.6 SQL Injection

Posted by deepcore under exploit (No Respond)

Rocket LMS version 1.6 suffers from a remote SQL injection vulnerability.

Social Share Button 2.2.3 SQL Injection

Posted by deepcore under exploit (No Respond)

Social Share Buttons version 2.2.3 suffers from a remote SQL injection vulnerability.

SAP SAProuter Improper Access Control

Posted by deepcore under exploit (No Respond)

SAP SAProuter suffers from an improper access control vulnerability where permitting loopback traffic can lead to unexpected behavior.

Palo Alto Networks Authenticated Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an OS command injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS versions prior to 10.0.1, 9.1.4 and 9.0.10.

SAP SAPControl Web Service Interface Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

SAPControl Web Service Interface (sapstartsrv) suffers from a privilege escalation vulnerability via a race condition.