Subscribe via feed.
Archive for March, 2023

Zyxel Unauthenticated LAN Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in the zhttpd binary (/bin/zhttpd). It is present on more than 40 Zyxel routers and CPE devices. The code execution vulnerability can only be exploited by an attacker if the zhttp webserver is reachable. No authentication is required. After exploitation, an attacker will be able to execute any […]

Nation-State Threat Actors Exploited Zero Days The Most In 2022

Posted by deepcore under exploit (No Respond)

Adobe Connect 11.4.5 / 12.1.5 Local File Disclosure

Posted by deepcore under exploit (No Respond)

Adobe Connect versions 11.4.5 and below as well as versions 12.1.5 and below suffer from a file disclosure vulnerability.

Yoga Class Registration 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Yoga Class Registration version 1.0 suffers from a remote SQL injection vulnerability.

Human Resources Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Human Resources Management System version 1.0 suffers from a remote SQL injection vulnerability.

Online Pizza Ordering System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Pizza Ordering System version 1.0 suffers from a remote SQL injection vulnerability.

Yoga Class Registration System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Yoga Class Registration System version 1.0 suffers from a cross site scripting vulnerability.

Medicine Tracker System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Medicine Tracker System version 1.0 suffers from a cross site scripting vulnerability.

Music Gallery Site 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Music Gallery Site version 1.0 suffers from a cross site scripting vulnerability.

Shannon Baseband NrSmPcoCodec Intra-Object Overflow

Posted by deepcore under exploit (No Respond)

There is an intra-object overflow in Shannon Baseband, inside the 5G SM protocol implementation (NrSmMsgCodec as it is called in Shannon according to debug strings), when decoding the Extended protocol configuration options message (IEI = 0x7B).