Subscribe via feed.
Posts under exploit

eXtplorer 2.1.14 Authentication Bypass / Remote Code Execution

Posted by deepcore under exploit (No Respond)

eXtplorer version 2.1.14 suffers from authentication bypass and remote code execution vulnerabilities.

Google Chrome 109.0.5414.74 Unsafe Library Load

Posted by deepcore under exploit (No Respond)

Google Chrome version 109.0.5414.74 on Ubuntu attempts to load libnssckbi.so from a user-writable location and if missing, a replacement piece of malware can be used by an attacker to achieve code execution. Although privilege escalation is not likely as an attacker would already need access to the user’s privilege level to place the malware, it […]

FlatCore CMS 2.1.1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

FlatCore CMS version 2.1.1 suffers from a persistent cross site scripting vulnerability.

Clansphere CMS 2011.4 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Clansphere CMS version 2011.4 suffers from a persistent cross site scripting vulnerability.

Zoneminder Log Injection / XSS / Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

Zoneminder versions prior to 1.37.24 suffers from log injection, persistent cross site scripting, and cross site request forgery bypass vulnerabilities.

WiFi Mouse 1.8.3.2 Remote Code Execution

Posted by deepcore under exploit (No Respond)

WiFi Mouse version 1.8.3.2 suffers from a remote code execution vulnerability.

Grafana 6.2.4 HTML Injection

Posted by deepcore under exploit (No Respond)

Grafana versions 6.2.4 and below suffer from an html injection vulnerability.

Webgrind 1.1 Cross Site Scripting / Remote Code Execution

Posted by deepcore under exploit (No Respond)

Webgrind version 1.1 suffers from remote code execution and cross site scripting vulnerabilities.

Scdbg 1.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

Scdbg version 1.0 suffers from a buffer overflow vulnerability that can cause a denial of service condition.

Hex Workshop 6.7 Buffer Overflow / Denial Of Service

Posted by deepcore under exploit (No Respond)

Hex Workshop version 6.7 is vulnerable to denial of service via command line file arguments and control of the Structured Exception Handler (SEH) records.