Subscribe via feed.
Archive for October, 2022

[webapps] WordPress Plugin ImageMagick-Engine 1.7.4 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin ImageMagick-Engine 1.7.4 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

http://kaokum.go.th/m6.htm

Posted by deepcore under defacement (No Respond)

http://kaokum.go.th/m6.htm notified by magelang6etar

Tags:

http://wianglocal.go.th/m6.htm

Posted by deepcore under defacement (No Respond)

http://wianglocal.go.th/m6.htm notified by magelang6etar

Tags:

macOS 12.3.1 Local Root

Posted by deepcore under exploit (No Respond)

This is a write up demonstrating how to get root on macOS 12.3.1 using CoreTrust and DriverKit bugs. Included is the spawn_root proof of concept.

Zentao Project Management System 17.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Zentao Project Management System version 17.0 suffers from an authenticated remote code execution vulnerability.

Crealogix EBICS Cross Site Scripting

Posted by deepcore under exploit (No Respond)

During a penetration test of an Electronic Banking Internet Communication Standard (EBICS) environment, Pentagrid observed a cross site scripting vulnerability in the EBICS banking implementation developed by CREALOGIX AG and used by many banks.

Web Based Student Clearance 1.0 Shell Upload

Posted by deepcore under exploit (No Respond)

Web Based Student Clearance version 1.0 suffers from a remote shell upload vulnerability.

Joomla Vik Rent Car 1.14 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Joomla Vik Rent Car extension version 1.14 suffers from a cross site scripting vulnerability.

WordPress / Joomla JReviews 4.1.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress / Joomla JReviews extension version 4.1.5 suffers from a cross site scripting vulnerability.

WordPress eCommerce Product Catalog 3.0.70 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress eCommerce Product Catalog plugin version 3.0.70 suffers from a cross site scripting vulnerability.