Subscribe via feed.
Archive for December, 2022

Bangresta 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Bangresta version 1.0 suffers from a remote SQL injection vulnerability.

Syncovery For Linux Web-GUI Authenticated Remote Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an authenticated command injection vulnerability in the Web GUI of Syncovery File Sync and Backup Software for Linux. Successful exploitation results in remote code execution under the context of the root user. Syncovery allows an authenticated user to create jobs, which are executed before/after a profile is run. Jobs can contain […]

Acronis TrueImage XPC Privilege Escalation

Posted by deepcore under exploit (No Respond)

Acronis TrueImage versions 2019 update 1 through 2021 update 1 are vulnerable to privilege escalation. The com.acronis.trueimagehelper helper tool does not perform any validation on connecting clients, which gives arbitrary clients the ability to execute functions provided by the helper tool with root privileges.

SOUND4 Server Service 4.1.102 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

SOUND4 Server Service version 4.1.102 suffers from an unquoted search path issue impacting the service SOUND4 Server for Windows. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in […]

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a cross site request forgery vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Authorization Bypass

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from an authorization bypass due to an insecure direct object reference vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Insufficient Session Expiration

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffers from an insufficient session expiration vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Disconnect Webmonitor User Denial Of Service

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below allows an unauthenticated attacker to disconnect the current monitoring user from listening/monitoring and takeover the radio stream on a specific channel.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x password SQL Injection

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a password SQL injection vulnerability that allows for authentication bypass.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x username SQL Injection

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a username SQL injection vulnerability that allows for authentication bypass.