Subscribe via feed.
Archive for March, 2023

Ancillary Function Driver (AFD) For Winsock Privilege Escalation

Posted by deepcore under exploit (No Respond)

A vulnerability exists in the Windows Ancillary Function Driver for Winsock (afd.sys) can be leveraged by an attacker to escalate privileges to those of NT AUTHORITY\SYSTEM. Due to a flaw in AfdNotifyRemoveIoCompletion, it is possible to create an arbitrary kernel Write-Where primitive, which can be used to manipulate internal I/O ring structures and achieve local […]

http://sratong.go.th

Posted by deepcore under defacement (No Respond)

http://sratong.go.th notified by NuLz404

Tags:

Beauty Salon 1.0 Remote Shell Upload

Posted by deepcore under exploit (No Respond)

Beauty Salon version 1.0 suffers from a remote shell upload vulnerability.

YouPHPTube 7.8 Local File Inclusion / Directory Traversal

Posted by deepcore under exploit (No Respond)

YouPHPTube versions 7.8 and below suffer from local file inclusion and directory traversal vulnerabilities.

SuperMailer 11.20 Buffer Overflow / Denial Of Service

Posted by deepcore under exploit (No Respond)

SuperMailer version 11.20 suffers from a denial of service vulnerability.

Online Shopping System Advanced 1.0 XSS / SQL Injection / Code Execution

Posted by deepcore under exploit (No Respond)

Online Shopping System Advanced version 1.0 suffers from code execution, cross site scripting, and remote SQL injection vulnerabilities.

WordPress Jetpack 11.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress Jetpack plugin version 11.4 suffers from a cross site scripting vulnerability.

HDD Health 4.2.0.112 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

HDD Health version 4.2.0.112 suffers from an unquoted service path vulnerability.

SugarSync 4.1.3 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

SugarSync version 4.1.3 suffers from an unquoted service path vulnerability.

Tapo C310 RTSP Server 1.3.0 Unauthorized Video Stream Access

Posted by deepcore under exploit (No Respond)

Tapo C310 RTSP server version 1.3.0 suffers from an unauthorized video stream access vulnerability.