Subscribe via feed.
Archive for February, 2023

Windows Kernel Dangling Registry Link Node Use-After-Free

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a use-after-free vulnerability due to a dangling registry link node under paged pool memory pressure.

Fortra GoAnywhere MFT Unsafe Deserialization Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an object deserialization vulnerability in Fortra GoAnywhere MFT.

Zoho ManageEngine Endpoint Central / MSP 10.1.2228.10 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine Endpoint Central and MSP versions 10.1.2228.10 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the Endpoint Central SAML endpoint. Note […]

SOUND4 LinkAndShare Transmitter 1.1.2 Format String Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

SOUND4 LinkAndShare Transmitter version 1.1.2 suffers from a format string memory leak and stack buffer overflow vulnerability because it fails to properly sanitize user supplied input when calling the getenv() function from MSVCR120.DLL resulting in a crash overflowing the memory stack and leaking sensitive information. The attacker can abuse the username environment variable to trigger […]

SOUND4 LinkAndShare Transmitter 1.1.2 Format String Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

SOUND4 LinkAndShare Transmitter version 1.1.2 suffers from a format string memory leak and stack buffer overflow vulnerability because it fails to properly sanitize user supplied input when calling the getenv() function from MSVCR120.DLL resulting in a crash overflowing the memory stack and leaking sensitive information. The attacker can abuse the username environment variable to trigger […]

Nagios XI 5.7.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in the windowswmi, switch, and cloud-vm configuration wizards that allow an authenticated user to perform remote code execution on Nagios XI versions 5.5.6 to 5.7.5 as the apache user. Valid credentials for a Nagios XI user are required. This module has […]

ManageEngine ADSelfService Plus Unauthenticated SAML Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine AdSelfService Plus versions 6210 and below. Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ADSelfService Plus SAML endpoint. Note that the target […]

ManageEngine ADSelfService Plus Unauthenticated SAML Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine AdSelfService Plus versions 6210 and below. Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ADSelfService Plus SAML endpoint. Note that the target […]

Material Dashboard 2 SQL Injection

Posted by deepcore under exploit (1 Respond)

Material Dashboard version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

101news By Mayuri K 1.0 SQL Injection

Posted by deepcore under exploit (1 Respond)

101news By Mayuri K version 1.0 suffers from multiple remote SQL injection vulnerabilities.