Subscribe via feed.
Archive for October, 2022

AVS Audio Converter 10.3 Stack Overflow

Posted by deepcore under exploit (No Respond)

AVS Audio Converter version 10.3 suffers from a stack overflow vulnerability.

Zimbra Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerable sudo configuration that permits the Zimbra user to execute postfix as root. In turn, postfix can execute arbitrary shellscripts, which means it can execute a root shell.

Fortinet FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authentication bypass vulnerability in the Fortinet FortiOS, FortiProxy, and FortiSwitchManager API to gain access to a chosen account and then adds an SSH key to the authorized_keys file of the chosen account, allowing you to login to the system with the chosen account. Successful exploitation results in remote code execution.

Intelbras WiFiber 120AC inMesh 1.1-220216 Command Injection

Posted by deepcore under exploit (No Respond)

Intelbras WiFiber 120AC inMesh version 1.1-220216 suffers from an authenticated command injection vulnerability.

Joomla OSG Courts Reservation 1.4.9 SQL Injection

Posted by deepcore under exploit (No Respond)

Joomla OSG Courts Reservation extension version 1.4.9 suffers from a remote SQL injection vulnerability.

Knap Advanced PHP Login 3.1.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Knap Advanced PHP Login version 3.1.3 suffers from a cross site scripting vulnerability.

Vicidial 2.14-783a Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Vicidial version 2.14-783a suffers from multiple cross site scripting vulnerabilities.

Garage Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Garage Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

Stripe Green Downloads 2.03 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Stripe Green Downloads version 2.03 suffers from a cross site scripting vulnerability.

WordPress ImageMagick-Engine 1.7.4 Remote Code Execution

Posted by deepcore under exploit (No Respond)

WordPress ImageMagick-Engine plugin versions 1.7.4 and below suffer from a remote code execution vulnerability.