Subscribe via feed.
Posts under exploit

Virtual Reception 1.0 Directory Traversal

Posted by deepcore under exploit (No Respond)

Virtual Reception version 1.0 suffers from a directory traversal vulnerability.

Lavasoft 4.1.0.409 Unquoted Service Path

Posted by deepcore under exploit (No Respond)

Lavasoft version 4.1.0.409 suffers from an unquoted service path vulnerability.

CrowdStrike Falcon Agent 6.44.15806 Uninstall Issue

Posted by deepcore under exploit (No Respond)

CrowdStrike Falcon Agent version 6.44.15806 has an uninstall bypass flaw that works without an installation token.

Forcepoint (Stonesoft VPN Client) 6.2.0 / 6.8.0 Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Forcepoint (Stonesoft VPN Client) versions 6.2.0 and 6.8.0 suffer from a privilege escalation vulnerability.

WordPress WPForms 1.7.8 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

WordPress WPForms plugin version 1.7.8 suffers from a cross site scripting vulnerability.

Eve-ng 5.0.1-13 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Eve-ng version 5.0.1-13 suffers from a cross site scripting vulnerability.

Ancillary Function Driver (AFD) For Winsock Privilege Escalation

Posted by deepcore under exploit (No Respond)

A vulnerability exists in the Windows Ancillary Function Driver for Winsock (afd.sys) can be leveraged by an attacker to escalate privileges to those of NT AUTHORITYSYSTEM. Due to a flaw in AfdNotifyRemoveIoCompletion, it is possible to create an arbitrary kernel Write-Where primitive, which can be used to manipulate internal I/O ring structures and achieve local […]

Ancillary Function Driver (AFD) For Winsock Privilege Escalation

Posted by deepcore under exploit (No Respond)

A vulnerability exists in the Windows Ancillary Function Driver for Winsock (afd.sys) can be leveraged by an attacker to escalate privileges to those of NT AUTHORITY\SYSTEM. Due to a flaw in AfdNotifyRemoveIoCompletion, it is possible to create an arbitrary kernel Write-Where primitive, which can be used to manipulate internal I/O ring structures and achieve local […]

Beauty Salon 1.0 Remote Shell Upload

Posted by deepcore under exploit (No Respond)

Beauty Salon version 1.0 suffers from a remote shell upload vulnerability.

YouPHPTube 7.8 Local File Inclusion / Directory Traversal

Posted by deepcore under exploit (No Respond)

YouPHPTube versions 7.8 and below suffer from local file inclusion and directory traversal vulnerabilities.