Exploit the possiblities

Recent Files

Files RSS Feed
Wapiti Web Application Vulnerability Scanner 3.0.0
Posted Jan 3, 2018
Authored by Nicolas Surribas | Site wapiti.sourceforge.net

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.

Changes: Ported to Python3. Added --list-modules and --resume-crawl options. Persister rewritten to use sqlite3 databases (for session management). Many other additions, updates, and improvements.
tags | tool, web, scanner, vulnerability
systems | unix
Joomla Advertisement Board Classifieds 3.2.0 Shell Upload
Posted Jan 3, 2018
Authored by Bilal Kardadou

Joomla Advertisement Board Classifieds extension version 3.2.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
Froxlor 0.9.37 HTML Injection
Posted Jan 3, 2018
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

Froxlor version 0.9.37 suffers from an html injection vulnerability.

tags | exploit
Atlassian Bamboo Code Execution / Argument Injection
Posted Jan 3, 2018
Authored by Atlassian

Atlassian Bamboo versions prior to 6.1.6 and 6.2.0 through 6.2.5 suffer from code execution and argument injection vulnerabilities.

tags | advisory, vulnerability, code execution
EMC xPression 4.5SP1 Patch 13 SQL Injection
Posted Jan 3, 2018
Authored by Pawel Gocyla

EMC xPression version 4.5SP1 Patch 13 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
b2evolution CMS 6.8.10 PHP Code Execution
Posted Jan 3, 2018
Authored by Anti Rais

b2evolution CMS versions 6.6.0 through 6.8.10 suffer from a php code execution vulnerability.

tags | exploit, php, code execution
Red Hat Security Advisory 2018-0005-01
Posted Jan 3, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-0005-01 - The eap7-jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise Application Platform running on the Amazon Web Services Elastic Compute Cloud. With this update, the eap7-jboss-ec2-eap package has been updated to ensure compatibility with Red Hat JBoss Enterprise Application Platform 7.0.9.

tags | advisory, web
systems | linux, redhat
Red Hat Security Advisory 2018-0004-01
Posted Jan 3, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-0004-01 - Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This release of Red Hat JBoss Enterprise Application Platform 7.0.9 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.0.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix: It was found that Apache Lucene would accept an object from an unauthenticated user that could be manipulated through subsequent post requests. An attacker could use this flaw to assemble an object that could permit execution of arbitrary code if the server enabled Apache Solr's Config API.

tags | advisory, java, arbitrary
systems | linux, redhat
Red Hat Security Advisory 2018-0002-01
Posted Jan 3, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-0002-01 - Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This release of Red Hat JBoss Enterprise Application Platform 7.0.9 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.0.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix: It was found that Apache Lucene would accept an object from an unauthenticated user that could be manipulated through subsequent post requests. An attacker could use this flaw to assemble an object that could permit execution of arbitrary code if the server enabled Apache Solr's Config API.

tags | advisory, java, arbitrary
systems | linux, redhat
Red Hat Security Advisory 2018-0003-01
Posted Jan 3, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-0003-01 - Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This release of Red Hat JBoss Enterprise Application Platform 7.0.9 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.0.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix: It was found that Apache Lucene would accept an object from an unauthenticated user that could be manipulated through subsequent post requests. An attacker could use this flaw to assemble an object that could permit execution of arbitrary code if the server enabled Apache Solr's Config API.

tags | advisory, java, arbitrary
systems | linux, redhat
Ubuntu Security Notice USN-3477-4
Posted Jan 3, 2018
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3477-4 - USN-3477-1 fixed vulnerabilities in Firefox. The update introduced a crash reporting issue where background tab crash reports were sent to Mozilla without user opt-in. This update fixes the problem. Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, read uninitialized memory, obtain sensitive information, bypass same-origin restrictions, bypass CSP protections, bypass mixed content blocking, spoof the addressbar, or execute arbitrary code. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary, spoof, vulnerability
systems | linux, ubuntu
WordPress Smart Google Code Inserter SQL Injection
Posted Jan 3, 2018
Authored by Benjamin Lim

WordPress Smart Google Code Inserter plugin versions prior to 3.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
Joomla EXP Auto 4.2.3 SQL Injection
Posted Jan 3, 2018
Authored by Bilal Kardadou

Joomla EXP Auto extension version 4.2.3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
Joomla RealEstateManager 4.2.0 SQL Injection
Posted Jan 3, 2018
Authored by Bilal Kardadou

Joomla RealEstateManager extension version 4.2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
Joomla VehicleManager 3.9.15 SQL Injection
Posted Jan 3, 2018
Authored by Bilal Kardadou

Joomla VehicleManager extension version 3.9.15 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
Fortinet Installer Client 5.6 DLL Hijacking
Posted Jan 3, 2018
Authored by Souhardya Sardar, Rohit Bankoti

Fortinet Installer Client 5.6 for Windows PC suffers from a dll hijacking vulnerability.

tags | exploit
systems | windows
Joomla JomDirectory 4.4 SQL Injection
Posted Jan 2, 2018
Authored by Bilal Kardadou

Joomla JomDirectory extension version 4.4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
Clooud 1.4.0 Shell Upload
Posted Jan 2, 2018
Authored by indoushka

Clooud version 1.4.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
Lara Overflow 1.0 Cross Site Scripting
Posted Jan 2, 2018
Authored by ShanoWeb

Lara Overflow version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, overflow, xss
Career Portal 1.0 Cross Site Scripting
Posted Jan 2, 2018
Authored by ShanoWeb

Career Portal Online Job Search Script version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
Eventsys Events Management System 1.0 Cross Site Scripting
Posted Jan 2, 2018
Authored by ShanoWeb

Eventsys Events Management System version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
Your Doctor Medical And Doctor Website CMS 1.0 Cross Site Scripting
Posted Jan 2, 2018
Authored by ShanoWeb

Your Doctor Medical and Doctor Website CMS version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
Ebook CMS 1.0 Cross Site Scripting
Posted Jan 2, 2018
Authored by ShanoWeb

Ebook CMS version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
FAQin Congress 3 Call For Proposals
Posted Jan 2, 2018
Site faqin.org

FAQin Congress is a free invitation-only underground hacking event in Madrid, Spain being held March 1st through the 3rd, 2018. The call for proposals has been announced.

tags | paper, conference
Apple macOS IOHIDSystem Kernel Read/Write
Posted Jan 2, 2018
Authored by Siguza

This is a macOS kernel exploit based on an IOHIDFamily vulnerability.

tags | exploit, kernel
View Older Files →

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

Recent News

News RSS Feed
Ripple Becomes Second Most Valuable Crypto Coin
Posted Jan 3, 2018

tags | headline, bank, cryptography
New Ransomware Headache As Crooks Dump Bitcoin For Rival Cryptocurrencies
Posted Jan 3, 2018

tags | headline, malware, cybercrime, fraud
Forever 21 Investigation Reveals Malware Presence At Some Stores
Posted Jan 2, 2018

tags | headline, malware, bank, cybercrime, fraud
10 Things In Cybersecurity That You Might Have Missed In 2017
Posted Jan 2, 2018

tags | headline, hacker, government, privacy, data loss, nsa
Iranians Resist Internet Censorship Amid Deadly Street Protests
Posted Jan 2, 2018

tags | headline, government, iran, twitter, censorship
Top Security Challenges For 2018 - Part 1
Posted Jan 2, 2018

tags | headline, hacker, privacy, cybercrime, data loss
The Most Dangerous People On The Internet 2017
Posted Dec 31, 2017

tags | headline, government, usa, fraud
Hacks, Scams, And Attacks: Blockchain's 2017 Disasters
Posted Dec 31, 2017

tags | headline, hacker, bank, cybercrime, data loss, fraud, cryptography
Hackers Can Rickroll Sonos And Bose Speakers Over The Internet
Posted Dec 31, 2017

tags | headline, hacker, flaw
Nation-State Hacking: 2017 In Review
Posted Dec 31, 2017

tags | headline, hacker, malware, usa, russia, cyberwar, korea
View More News →

File Archive:

January 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    2 Files
  • 2
    Jan 2nd
    13 Files
  • 3
    Jan 3rd
    16 Files
  • 4
    Jan 4th
    0 Files
  • 5
    Jan 5th
    0 Files
  • 6
    Jan 6th
    0 Files
  • 7
    Jan 7th
    0 Files
  • 8
    Jan 8th
    0 Files
  • 9
    Jan 9th
    0 Files
  • 10
    Jan 10th
    0 Files
  • 11
    Jan 11th
    0 Files
  • 12
    Jan 12th
    0 Files
  • 13
    Jan 13th
    0 Files
  • 14
    Jan 14th
    0 Files
  • 15
    Jan 15th
    0 Files
  • 16
    Jan 16th
    0 Files
  • 17
    Jan 17th
    0 Files
  • 18
    Jan 18th
    0 Files
  • 19
    Jan 19th
    0 Files
  • 20
    Jan 20th
    0 Files
  • 21
    Jan 21st
    0 Files
  • 22
    Jan 22nd
    0 Files
  • 23
    Jan 23rd
    0 Files
  • 24
    Jan 24th
    0 Files
  • 25
    Jan 25th
    0 Files
  • 26
    Jan 26th
    0 Files
  • 27
    Jan 27th
    0 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

News Tags

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close