Subscribe via feed.
Posts under exploit

WebKit CSSCrossfadeValue::crossfadeChanged Use-After-Free

Posted by deepcore under exploit (No Respond)

WebKit suffers from a RenderMathMLToken use-after-free vulnerability in CSSCrossfadeValue::crossfadeChanged.

libCoreEntitlements CEContextQuery Arbitrary Entitlement Returns

Posted by deepcore under exploit (No Respond)

On newer macOS/iOS versions, entitlements in binary signature blobs are stored in the DER format. libCoreEntitlements.dylib is the userspace library for parsing and querying such entitlements. The kernel has its own version of this library inside the AppleMobileFileIntegrity module. libCoreEntitlements exposes several functions, such as, for example, to convert entitlements to a dictionary representation (e.g. […]

Windows Kernel NtNotifyChangeMultipleKeys Use-After-Free

Posted by deepcore under exploit (No Respond)

The Windows Kernel suffers from a use-after-free vulnerability due to bad handling of predefined keys in NtNotifyChangeMultipleKeys.

Gold Filled CRM 2.0 Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

Gold Filled CRM version 2.0 suffers from an unauthenticated arbitrary file upload vulnerability.

Online Food Ordering System 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Food Ordering System version 2.0 suffers from a remote SQL injection vulnerability.

2ad Guestbook 2.0 Database Disclosure

Posted by deepcore under exploit (No Respond)

2ad Guestbook version 2.0 suffers from a database disclosure vulnerability.

Blesta 5.4.1 Insecure Settings

Posted by deepcore under exploit (No Respond)

Blesta version 5.4.1 appears to leave a default administrative account in place post installation.

Deprixa Pro 7.5 Insecure Settings

Posted by deepcore under exploit (No Respond)

Deprixa Pro version 7.5 appears to leave a default administrative account in place post installation.

ChiKoi 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

ChiKoi version 1.0 suffers from a remote SQL injection vulnerability.

Flex 5.22 Insecure Settings

Posted by deepcore under exploit (No Respond)

Flex version 5.2.2 appears to leave a default administrative account in place post installation.