Subscribe via feed.
Archive for January, 2023

WordPress Slider Revolution 4.x.x Shell Upload

Posted by deepcore under exploit (No Respond)

WordPress Slider Revolution plugin versions 4.x.x suffer from a remote shell upload vulnerability.

ChiKoi New-MVC-SHOP 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ChiKoi New-MVC-SHOP version 1.0 suffers from a cross site scripting vulnerability.

Academy LMS 5.11 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Academy LMS version 5.11 suffers from a cross site scripting vulnerability.

WebKit CSSCrossfadeValue::crossfadeChanged Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a RenderMathMLToken use-after-free vulnerability in CSSCrossfadeValue::crossfadeChanged.

libCoreEntitlements CEContextQuery Arbitrary Entitlement Returns

Posted by deepcore under exploit (No Respond)

On newer macOS/iOS versions, entitlements in binary signature blobs are stored in the DER format. libCoreEntitlements.dylib is the userspace library for parsing and querying such entitlements. The kernel has its own version of this library inside the AppleMobileFileIntegrity module. libCoreEntitlements exposes several functions, such as, for example, to convert entitlements to a dictionary representation (e.g. […]

Windows Kernel NtNotifyChangeMultipleKeys Use-After-Free

Posted by deepcore under exploit (No Respond)

The Windows Kernel suffers from a use-after-free vulnerability due to bad handling of predefined keys in NtNotifyChangeMultipleKeys.

Gold Filled CRM 2.0 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Gold Filled CRM version 2.0 suffers from an unauthenticated arbitrary file upload vulnerability.

Online Food Ordering System 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Food Ordering System version 2.0 suffers from a remote SQL injection vulnerability.

2ad Guestbook 2.0 Database Disclosure

Posted by deepcore under exploit (No Respond)

2ad Guestbook version 2.0 suffers from a database disclosure vulnerability.

Blesta 5.4.1 Insecure Settings

Posted by deepcore under exploit (No Respond)

Blesta version 5.4.1 appears to leave a default administrative account in place post installation.