Cisco Catalyst 2960 with IOS version 12.2(55)SE11 ROCEM remote code execution exploit.
Category Archives: Security
Security
Solaris x86 / SPARC EXTREMEPARR dtappgather Privilege Escalation
Solaris versions 7 through 11 on both x86 and SPARC suffer from an EXTREMEPARR dtappgather local privilege escalation vulnerability.
Magento 2.1.6 Shell Upload / Cross Site Request Forgery
Magento versions 2.1.6 and below suffers from cross site request forgery and shell upload vulnerabilities.
WordPress BestWebSoft XSS / CSRF
53+ WordPress plugins by BestWebSoft suffer from cross site scripting and cross site request forgery vulnerabilities.
Red Hat Security Advisory 2017-0907-01
Red Hat Security Advisory 2017-0907-01 – The util-linux packages contain a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, these include the fdisk configuration tool and the login program. Security Fix: A race condition was found in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
PCMAN FTP Server 2.0.7 MKD Buffer Overflow
This Metasploit module exploits a buffer overflow vulnerability found in the MKD command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.
PCMAN FTP Server 2.0.7 NLST Buffer Overflow
This Metasploit module exploits a buffer overflow vulnerability found in the NLST command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.
PCMAN FTP Server 2.0.7 GET Buffer Overflow
This Metasploit module exploits a buffer overflow vulnerability found in the GET command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.
PCMAN FTP Server 2.0.7 ACCT Buffer Overflow
This Metasploit module exploits a buffer overflow vulnerability found in the ACCT command of the PCMAN FTP version 2.0.7 Server. This requires authentication but by default anonymous credentials are enabled.
Vuln: Trend Micro Threat Discovery Appliance CVE-2016-7552 Directory Traversal Vulnerability
Trend Micro Threat Discovery Appliance CVE-2016-7552 Directory Traversal Vulnerability