Subscribe via feed.
Posts under exploit

CoreDial sipXcom sipXopenfire 21.04 Remote Command Execution / Weak Permissionsundefined

Posted by deepcore under exploit (No Respond)

CoreDial sipXcom sipXopenfire versions 21.04 and below suffer from XMPP message system command argument injection and insecure service file permissions that when chained together gives root.

Oracle 19c Access Bypass

Posted by deepcore under exploit (No Respond)

Oracle Database Vault had a flaw that would allow unauthorized privileged users to extract data from a protected table. Oracle 19c versions 19.18 and below are affected. Fixed in the Oracle Critical Patch Update October 2022.

Arris DG3450 AR01.02.056.18_041520_711.NCS.10 XSS / Missing Authentication

Posted by deepcore under exploit (No Respond)

Arris DG3450 cable gateway version AR01.02.056.18_041520_711.NCS.10 suffers from cross site scripting and missing authentication vulnerabilities.

Arris DG3450 AR01.02.056.18_041520_711.NCS.10 XSS / Missing Authentication

Posted by deepcore under exploit (No Respond)

Arris DG3450 cable gateway version AR01.02.056.18_041520_711.NCS.10 suffers from cross site scripting and missing authentication vulnerabilities.

CoreDial sipXcom sipXopenfire 21.04 Remote Command Execution / Weak Permissions

Posted by deepcore under exploit (No Respond)

CoreDial sipXcom sipXopenfire versions 21.04 and below suffer from XMPP message system command argument injection and insecure service file permissions that when chained together gives root.

Purchase Order Management 1.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Purchase Order Management version 1.0 appears to suffer from a cross site scripting vulnerability due to printing errors with a malicious password payload.

Purchase Order Management 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Purchase Order Management version 1.0 suffers from a remote SQL injection vulnerability.

Android GKI Kernels Contain Broken Non-Upstream Speculative Page Faults MM Code

Posted by deepcore under exploit (No Respond)

Android GKI kernels contain broken non-upstream Speculative Page Faults MM code that can lead to multiple use-after-free conditions.

Agilebio Lab Collector 4.234 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Agilebio Lab Collector version 4.234 suffers from a remote code execution vulnerability.

GoAnywhere MFT Zero Day Disclosures Seem Slow

Posted by deepcore under exploit (No Respond)