Subscribe via feed.
Archive for October, 2022

Spring Cloud Gateway 3.1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability in Spring Cloud Gateway versions 3.0.0 through 3.0.6 and 3.1.0. The vulnerability can be exploited when the Gateway Actuator endpoint is enabled, exposed and unsecured. An unauthenticated attacker can use SpEL expressions to execute code and take control of the victim machine.

pfSense pfBlockerNG 2.1.4_26 Shell Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module leverages a remote shell upload vulnerability in pfSense pfBlockerNG plugin versions 2.1.4_26 and below. Note that version 3.x is unaffected.

MiniDVBLinux 5.4 Remote Root Command Injection

Posted by deepcore under exploit (No Respond)

MiniDVBLinux version 5.4 suffers from an OS command injection vulnerability. This can be exploited to execute arbitrary commands with root privileges.

Backdoor.Win32.Redkod.d MVID-2022-0649 Hardcoded Credential

Posted by deepcore under exploit (No Respond)

Backdoor.Win32.Redkod.d malware suffers from a hardcoded credential vulnerability.

WiFi File Transfer 1.0.8 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WiFi File Transfer version 1.0.8 suffers from a cross site scripting vulnerability.

MiniDVBLinux 5.4 Remote Root Command Execution

Posted by deepcore under exploit (No Respond)

MiniDVBLinux version 5.4 suffers from an OS command execution vulnerability. This can be exploited to execute arbitrary commands as root through the command GET parameter in /tpl/commands.sh.

WordPress Photo Gallery 1.8.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Photo Gallery plugin version 1.8.0 suffers from a cross site scripting vulnerability.

MiniDVBLinux 5.4 Arbitrary File Read

Posted by deepcore under exploit (No Respond)

MiniDVBLinux versions 5.4 and below suffer from an arbitrary file disclosure vulnerability.

Apple Security Advisory 2022-10-10-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2022-10-10-1 – iOS 16.0.3 addresses a denial of service vulnerability.

Tags: , ,

Apple Music Android Application 3.10.2 Man-In-The-Middle

Posted by deepcore under Apple (No Respond)

Apple Music Android Application versions 3.8.0 through 3.10.2 suffer from a man-in-the-middle vulnerability.

Tags: , ,