Subscribe via feed.
Archive for April, 2023

https://nampirejo-temanggung.temanggungkab.go.id

Posted by under defacement, Security (No Respond)

https://nampirejo-temanggung.temanggungkab.go.id notified by Indonesia Attacker

Chitor CMS 1.1.2 SQL Injection

Posted by deepcore under exploit (No Respond)

Chitor CMS version 1.1.2 suffers from a remote SQL injection vulnerability. Original discovery of this finding is attributed to msd0pe in April of 2023.

Multi-Vendor Online Groceries Management System 1.0 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Multi-Vendor Online Groceries Management System version 1.0 suffers from a remote code execution vulnerability.

Telit Cinterion IoT Traversal / Escalation / Bypass / Heap Overflow

Posted by deepcore under exploit (No Respond)

This is an extension of research on the original findings of CVE-2020-15858 in Telit Cinterion IoT devices. Numerous issues have been discovered including path traversal, Java privilege elevation, AT commands whitelist / blacklist bypass, a heap overflow in fragmented SMS, and more.

http://www.namkrai.go.th

Posted by deepcore under defacement (No Respond)

http://www.namkrai.go.th notified by Ajoyy

Tags:

http://www.koisoong.go.th

Posted by deepcore under defacement (No Respond)

http://www.koisoong.go.th notified by Ajoyy

Tags:

[webapps] KodExplorer 4.49 – CSRF to Arbitrary File Upload

Posted by deepcore under Security (No Respond)

KodExplorer 4.49 – CSRF to Arbitrary File Upload

Tags: ,

Chrome media::mojom::VideoFrame Missing Validation

Posted by deepcore under exploit (No Respond)

Chrome suffers from an issue where the traits for media::mojom::VideoFrame do not perform any validation on the stride and offset parameters when deserializing untrusted message data.

Chrome GL_ShaderBinary Untrusted Process Exposure

Posted by deepcore under exploit (No Respond)

Chrome has an issue where the GL_ShaderBinary is exposed to untrusted processes.

Chrome SpvGetMappedSamplerName Out-Of-Bounds String Copy

Posted by deepcore under exploit (No Respond)

Chrome has an issue where there is an out-of-bounds string copy that can occur when parsing a uniform sampler name in SpvGetMappedSamplerName.