Subscribe via feed.
Archive for April, 2023

GDidees CMS 3.9.1 Local File Disclosure / Directory Traversal

Posted by deepcore under exploit (No Respond)

GDidees CMS version 3.9.1 suffers from file disclosure and directory traversal vulnerabilities.

Bang Resto 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Bang Resto version 1.0 suffers from a cross site scripting vulnerability.

Bang Resto 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Bang Resto version 1.0 suffers from multiple SQL injection vulnerabilities. Original discovery of SQL injection in this version is attributed to nu11secur1ty in December of 2022.

AspEmail 5.6.0.2 Weak Permissions / Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

AspEmail version 5.6.0.2 suffers from weak permission vulnerability that allows for local privilege escalation.

http://data.skc.go.th/crush.html

Posted by deepcore under defacement (No Respond)

http://data.skc.go.th/crush.html notified by ./KeyzNet

Tags:

Zero Day In Google Chrome Patched: Bug Exploited In The Wild

Posted by deepcore under exploit (No Respond)

AspEmail 5.6.0.2 Weak Permissions / Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

AspEmail version 5.6.0.2 suffers from weak permission vulnerability that allows for local privilege escalation.

Microsoft Word Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Word appears to suffer from a remote code execution vulnerability when a user load a malicious file that reaches out to an attacker-controller server to get a hostile payload.

Microsoft Word Remote Code Execution

Posted by deepcore under exploit (No Respond)

Microsoft Word appears to suffer from a remote code execution vulnerability when a user load a malicious file that reaches out to an attacker-controller server to get a hostile payload.

Microsoft Windows Kernel Transactional Registry Key Rename Issues

Posted by deepcore under exploit (No Respond)

The Microsoft Windows Kernel suffers from multiple issues in the prepare/commit phase of a transactional registry key rename.