Subscribe via feed.
Archive for March, 2023

Linksys AX3200 1.1.00 Command Injection

Posted by deepcore under exploit (No Respond)

Linksys AX3200 version 1.1.00 suffers from a remote command injection vulnerability.

MAN-EAM-0003 3.2.4 XML Injection

Posted by deepcore under exploit (No Respond)

MAN-EAM-0003 version 3.2.4 suffers from an XML external entity injection vulnerability.

wkhtmltopdf 0.12.6 Server-Side Request Forgery

Posted by deepcore under exploit (No Respond)

wkhtmltopdf version 0.12.6 suffers from a server-side request forgery vulnerability.

Bitbucket 7.0.0 Remote Command Execution

Posted by deepcore under exploit (No Respond)

Bitbucket version 7.0.0 suffers from a remote command execution vulnerability.

Sales Tracker Management System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Sales Tracker Management System version 1.0 suffers from a cross site scripting vulnerability.

Online Graduate Tracer System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Graduate Tracer System version 1.0 suffers from a remote SQL injection vulnerability.

Joomla! 4.2.7 Unauthenticated Information Disclosure

Posted by deepcore under exploit (No Respond)

Joomla! versions prior to 4.2.8 suffer from an unauthenticated information disclosure vulnerability.

RSA NetWitness Endpoint EDR Agent 12.x Incorrect Access Control / Code Execution

Posted by deepcore under exploit (No Respond)

RSA NetWitness Endpoint EDR Agent version 12.x suffers from incorrect access controls that allow for code execution. It allows local users to stop the Endpoint Windows agent from sending the events to a SIEM or make the agent run user-supplied commands.

http://www.klongkhwangsao.go.th/Scorpiol.html

Posted by deepcore under defacement (No Respond)

http://www.klongkhwangsao.go.th/Scorpiol.html notified by Scorpiol

Tags:

RSA NetWitness Endpoint EDR Agent 12.x Incorrect Access Control / Code Execution

Posted by deepcore under exploit (No Respond)

RSA NetWitness Endpoint EDR Agent version 12.x suffers from incorrect access controls that allow for code execution. It allows local users to stop the Endpoint Windows agent from sending the events to a SIEM or make the agent run user-supplied commands.