Subscribe via feed.
Posts under exploit

Oracle DBMS_REDACT Dynamic Data Masking Bypass

Posted by deepcore under exploit (No Respond)

Proof of concept overview on how the DBMS_REDACT Dynamic Data Masking security feature in Oracle can be bypassed. Affected versions include 19c and 21c.

Nexxt Router Firmware 42.103.1.5095 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Nexxt Router Firmware version 42.103.1.5095 authenticated remote code execution exploit that enables telnetd.

Oracle DBMS_REDACT Dynamic Data Masking Bypass

Posted by deepcore under exploit (No Respond)

Proof of concept overview on how the DBMS_REDACT Dynamic Data Masking security feature in Oracle can be bypassed. Affected versions include 19c and 21c.

BDWeb-Link LMS 1.11.5 SQL Injection

Posted by deepcore under exploit (No Respond)

BDWeb-Link LMS version 1.11.5 suffers from a remote SQL injection vulnerability.

SugarCRM Shell Upload

Posted by deepcore under exploit (No Respond)

SugarCRM versions up to 12.2.0 suffer from a remote shell upload vulnerability.

Oracle Unified Audit Policy Bypass

Posted by deepcore under exploit (No Respond)

Oracle versions 12.1.0.2, 12.2.0.1, and 19c suffer from a Unified Audit Policy bypass vulnerability.

crewjam/saml Signature Bypass

Posted by deepcore under exploit (No Respond)

The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.

Chrome Synchronous Mojo Use-After-Free

Posted by deepcore under exploit (No Respond)

A design flaw in the Chrome Synchronous Mojo message handling introduces unexpected reentrancy and allows for multiple use-after-free vulnerabilities.

Packet Storm New Exploits For December, 2022

Posted by deepcore under exploit (No Respond)

This archive contains all of the 82 exploits added to Packet Storm in December, 2022.

Packet Storm New Exploits For 2022

Posted by deepcore under exploit (No Respond)

Complete comprehensive archive of all 1,384 exploits added to Packet Storm in 2022.