Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter

Vulnerabilities

GitStack 2.3.10 Unauthenticated Remote Code Execution

$_SERVER['PHP_AUTH_PW'] is directly passed to exec function.

18-01-2018

1 MIN READ

Vulnerabilities

QNAP HelpDesk 1.1.12 Privilege Escalation using SQL Injection

We can access registerExternalLog without any user credentials.

25-10-2017

2 MIN READ

Vulnerabilities

Netgear ReadyNAS Surveillance 1.4.3-16 Unauthenticated RCE

$_GET['uploaddir'] is not escaped and passed to system() through $tmp_upload_dir.

29-09-2017

1 MIN READ

Vulnerabilities

Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution

CVE-2017-11151 allows remote attackers to upload arbitrary files to the specified directories.

17-09-2017

1 MIN READ

Vulnerabilities

ManageEngine Desktop Central 10 Build 100087 RCE

When uploading a file, the FileUploadServlet class does not check the user-controlled fileName parameter using hasVulnerabilityInFileName function.

24-07-2017

3 MIN READ

Vulnerabilities

QNAP PhotoStation 5.2.4 and MusicStation 4.8.4 Authentication Bypass

$_COOKIE[STATIONSID] is not escaped.

10-05-2017

1 MIN READ

Vulnerabilities

Dell Customer Connect 1.3.28.0 Privilege Escalation

RunImpersonated() executes given function in the context of currently logged in user.

25-04-2017

3 MIN READ

Vulnerabilities

CyberGhost 6.0.4.2205 Privilege Escalation

CG6Service service has interesting method SetPeLauncherState which allows launch the debugger automatically for every process we want using Image File Execution Options

06-03-2017

1 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter