Subscribe via feed.
Archive for March, 2023

Purchase Order Management 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Purchase Order Management version 1.0 suffers from a remote SQL injection vulnerability.

Purchase Order Management 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Purchase Order Management version 1.0 appears to suffer from a cross site scripting vulnerability due to printing errors with a malicious password payload.

Android GKI Kernels Contain Broken Non-Upstream Speculative Page Faults MM Code

Posted by deepcore under exploit (No Respond)

Android GKI kernels contain broken non-upstream Speculative Page Faults MM code that can lead to multiple use-after-free conditions.

Agilebio Lab Collector 4.234 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Agilebio Lab Collector version 4.234 suffers from a remote code execution vulnerability.

https://www.onep.go.th/vz.txt

Posted by deepcore under defacement (No Respond)

https://www.onep.go.th/vz.txt notified by aDriv4

Tags:

GoAnywhere MFT Zero Day Disclosures Seem Slow

Posted by deepcore under exploit (No Respond)

Agilebio Lab Collector 4.234 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Agilebio Lab Collector version 4.234 suffers from a remote code execution vulnerability.

NetBSD hfslib_reada_node_offset Overflow

Posted by deepcore under exploit (No Respond)

NetBSD hfslib_reada_node_offset local overflow proof of concept exploit.

Barracuda CloudGen WAN OS Command Injection

Posted by deepcore under exploit (No Respond)

Barracuda CloudGen WAN provides a private edge appliance for hybrid deployments. An authenticated user in the administration interface for the private edge virtual appliance can inject arbitrary OS commands via the /ajax/update_certificate endpoint. Versions prior to v8.* hotfix 1089 are affected.

Barracuda CloudGen WAN OS Command Injection

Posted by deepcore under exploit (No Respond)

Barracuda CloudGen WAN provides a private edge appliance for hybrid deployments. An authenticated user in the administration interface for the private edge virtual appliance can inject arbitrary OS commands via the /ajax/update_certificate endpoint. Versions prior to v8.* hotfix 1089 are affected.