Subscribe via feed.
Archive for December, 2022

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x ICMP Flood Attack

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below allow an unauthenticated attacker to send network signals to an arbitrary target host that can be abused in an ICMP flooding attack. This includes the utilization of the ping, traceroute and nslookup commands through ping.php, traceroute.php and dns.php respectively.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Hardcoded Credentials

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a hardcoded credential vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Directory Traversal / File Write

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from an unauthenticated directory traversal file write vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Persistent Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a username persistent cross site scripting vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Information Disclosure

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from an information disclosure vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x dns.php Command Injection

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x and below suffer from a conditional command injection vulnerability in dns.php.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Radio Steam Disclosure

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from an unauthenticated radio stream disclosure vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x ping.php Command Injection

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x and below suffer from a conditional command injection vulnerability in ping.php.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x Unauthenticated File Disclosure

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x and below suffer from an unauthenticated file disclosure vulnerability.

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x services Command Injection

Posted by deepcore under exploit (No Respond)

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below suffer from a services related authenticated command injection vulnerability.