Subscribe via feed.
Posts under exploit

Zyxel Unauthenticated LAN Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in the zhttpd binary (/bin/zhttpd). It is present on more than 40 Zyxel routers and CPE devices. The code execution vulnerability can only be exploited by an attacker if the zhttp webserver is reachable. No authentication is required. After exploitation, an attacker will be able to execute any […]

Now Patched Outlook Zero Day Gains PoC And Growing Concerns

Posted by deepcore under exploit (No Respond)

Hackers Drain Bitcoin ATMs Of $1.5 Million By Exploiting 0-Day Bug

Posted by deepcore under exploit (No Respond)

Zyxel Unauthenticated LAN Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a buffer overflow in the zhttpd binary (/bin/zhttpd). It is present on more than 40 Zyxel routers and CPE devices. The code execution vulnerability can only be exploited by an attacker if the zhttp webserver is reachable. No authentication is required. After exploitation, an attacker will be able to execute any […]

Nation-State Threat Actors Exploited Zero Days The Most In 2022

Posted by deepcore under exploit (No Respond)

Adobe Connect 11.4.5 / 12.1.5 Local File Disclosure

Posted by deepcore under exploit (No Respond)

Adobe Connect versions 11.4.5 and below as well as versions 12.1.5 and below suffer from a file disclosure vulnerability.

Human Resources Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Human Resources Management System version 1.0 suffers from a remote SQL injection vulnerability.

Yoga Class Registration 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Yoga Class Registration version 1.0 suffers from a remote SQL injection vulnerability.

Online Pizza Ordering System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Pizza Ordering System version 1.0 suffers from a remote SQL injection vulnerability.

Yoga Class Registration System 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Yoga Class Registration System version 1.0 suffers from a cross site scripting vulnerability.