Subscribe via feed.
Archive for March, 2023

Apple Security Advisory 2023-03-27-8

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2023-03-27-8 – Safari 16.4 addresses bypass vulnerabilities.

Tags: , ,

Apple Security Advisory 2023-03-27-9

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2023-03-27-9 – Studio Display Firmware Update 16.4 addresses a code execution vulnerability.

Tags: , ,

https://bkkchem.bangkok.go.th/webapp/storage/good.txt

Posted by deepcore under defacement (No Respond)

https://bkkchem.bangkok.go.th/webapp/storage/good.txt notified by ChyBee1337

Tags:

SolarWinds Information Service (SWIS) Remote Command Execution

Posted by deepcore under exploit (No Respond)

The SolarWinds Information Service (SWIS) is vulnerable to remote code execution by way of a crafted message received through the AMQP message queue. A malicious user that can authenticate to the AMQP service can publish such a crafted message whose body is a serialized .NET object which can lead to OS command execution as NT […]

eXtplorer 2.1.14 Authentication Bypass / Remote Code Execution

Posted by deepcore under exploit (No Respond)

eXtplorer version 2.1.14 suffers from authentication bypass and remote code execution vulnerabilities.

Google Chrome 109.0.5414.74 Unsafe Library Load

Posted by deepcore under exploit (No Respond)

Google Chrome version 109.0.5414.74 on Ubuntu attempts to load libnssckbi.so from a user-writable location and if missing, a replacement piece of malware can be used by an attacker to achieve code execution. Although privilege escalation is not likely as an attacker would already need access to the user’s privilege level to place the malware, it […]

FlatCore CMS 2.1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

FlatCore CMS version 2.1.1 suffers from a persistent cross site scripting vulnerability.

Clansphere CMS 2011.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Clansphere CMS version 2011.4 suffers from a persistent cross site scripting vulnerability.

Zoneminder Log Injection / XSS / Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Zoneminder versions prior to 1.37.24 suffers from log injection, persistent cross site scripting, and cross site request forgery bypass vulnerabilities.

WiFi Mouse 1.8.3.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

WiFi Mouse version 1.8.3.2 suffers from a remote code execution vulnerability.