Subscribe via feed.
Archive for January, 2023

NetChess 2.1 Buffer Overflow

Posted by deepcore under exploit (No Respond)

NetChess version 2.1 suffers from a buffer overflow vulnerability.

OpenText Extended ECM 22.3 File Deletion / LFI / Privilege Escsalation

Posted by deepcore under exploit (No Respond)

OpenText Extended ECM versions 16.2.2 through 22.3 suffer from arbitrary file deletion, information disclosure, local file inclusion, and privilege escalation vulnerabilities.

Patient Record Management System 1.0 Authentication Bypass

Posted by deepcore under exploit (No Respond)

Patient Record Management System version 1.0 suffers from an authentication bypass vulnerability during account recovery.

Solaris 10 dtprintinfo / libXm / libXpm Security Issues

Posted by deepcore under exploit (No Respond)

Multiple vulnerabilities have been discovered across Common Desktop Environment version 1.6, Motif version 2.1, and X.Org libXpm versions prior to 3.5.15 on Oracle Solaris 10 that can be chained together to achieve root.

Solaris 10 dtprintinfo Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Solaris 10 CDE local privilege escalation exploit that achieves root by injecting a fake printer via lpstat and uses a buffer overflow in libXM ParseColors().

http://www.bnk.go.th/f7xp.html

Posted by deepcore under defacement (No Respond)

http://www.bnk.go.th/f7xp.html notified by F7 Xpl0it3r

Tags:

SLIMS 9.5.2 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

SLIMS version 9.5.2 suffers from a cross site scripting vulnerability.

http://www.sdm.dmr.go.th/b.htm

Posted by deepcore under defacement (No Respond)

http://www.sdm.dmr.go.th/b.htm notified by Mr. BDKR28

Tags:

KesionCMS X 1.5 Add Administrator

Posted by deepcore under exploit (No Respond)

KesionCMS X version 1.5 suffers from a direct access add administrator vulnerability.

Yazilimi Jettweb Haber 3 SQL Injection

Posted by deepcore under exploit (No Respond)

Yazilimi Jettweb Haber version 3 suffers from a remote SQL injection vulnerability that allows for authentication bypass.