Subscribe via feed.
Archive for February, 2023

Kardex Mlog MCC 5.7.12+0-a203c2a213-master File Inclusion / Remote Code Execution

Posted by deepcore under exploit (No Respond)

Kardex Mlog MCC version 5.7.12+0-a203c2a213-master suffers from a file inclusion vulnerability that allows for remote code execution.

Atrocore 1.5.25 Shell Upload

Posted by deepcore under exploit (No Respond)

Atrocore version 1.5.25 suffers from a remote shell upload vulnerability.

Two Zero-Days Fixed In Patch Tuesday Can Escalate Privileges To SYSTEM

Posted by deepcore under exploit (No Respond)

Atrocore 1.5.25 Shell Upload

Posted by deepcore under exploit (No Respond)

Atrocore version 1.5.25 suffers from a remote shell upload vulnerability.

Arris Router Firmware 9.1.103 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Arris Router Firmware version 9.1.103 authenticated remote code execution exploit that has been tested against the TG2482A, TG2492, and SBG10 models.

Korenix JetWave Command Injection / Denial Of Service

Posted by deepcore under exploit (No Respond)

Multiple versions of Korenix JetWave suffer from authenticated command injection and denial of service vulnerabilities.

GitLab GitHub Repo Import Deserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

An authenticated user can import a repository from GitHub into GitLab. If a user attempts to import a repo from an attacker-controlled server, the server will reply with a Redis serialization protocol object in the nested default_branch. GitLab will cache this object and then deserialize it when trying to load a user session, resulting in […]

WordPress Quiz And Survey Master 8.0.8 Media Deletion

Posted by deepcore under exploit (No Respond)

WordPress Quiz and Survey Master plugin versions 8.0.8 and below suffer from a missing authentication vulnerability that allows an attacker to delete media from the WordPress instance.

WordPress Quiz And Survey Master 8.0.8 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

WordPress Quiz and Survey Master plugin versions 8.0.8 and below suffer from a cross site request forgery vulnerability.

B&R Systems Diagnostics Manager Cross Site Scripting

Posted by deepcore under exploit (No Respond)

B&R Systems Diagnostics Manager versions above or equal to 3.00 and below or equal to C4.93 suffer from a cross site scripting vulnerability.