exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 220 RSS Feed

Files

Packet Storm New Exploits For March, 2014
Posted Apr 1, 2014
Authored by Todd J. | Site packetstormsecurity.com

This archive contains all of the 220 exploits added to Packet Storm in March, 2014.

tags | exploit
systems | linux
SHA-256 | 51349b5abbde8e1fd6bd4fef4c6c16203f245c7bcdb7688e99fad92c2497ef0d
PhonerLite 2.14 Digest Information Leak
Posted Mar 31, 2014
Authored by Jason Ostrom

PhonerLite SIP soft phone version 2.14 is vulnerable to revealing SIP MD5 digest authenticated user credential hash via spoofed SIP INVITE message sent by a malicious 3rd party. After responding back to an authentication challenge to the BYE message, PhonerLite leaks the hashed MD5 digest credentials.

tags | exploit, spoof, info disclosure
advisories | CVE-2014-2560
SHA-256 | 7a34b13b986e3c819eec422d90f73dfa5a7fe4225fdb3fbe73a15891c3c278e5
EMC Cloud Tiering Appliance 10.0 XXE Injection
Posted Mar 31, 2014
Authored by Brandon Perry

EMC Cloud Tiering appliance version 10.0 suffers from an unauthenticated XXE injection vulnerability. Metasploit module proof of concept is included.

tags | exploit, proof of concept, xxe
SHA-256 | 8191ae1d7b8520f1907f9a4102488831c9cce91d284f870d73ce4c7105f6ce7c
Vanctech File Commander 1.1 LFI / File Upload
Posted Mar 31, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Vanctech File Commander version 1.1 for iOS suffers from local file inclusion and remote file upload vulnerabilities.

tags | exploit, remote, local, vulnerability, file inclusion, file upload
systems | apple, ios
SHA-256 | 4cdbd24ff9f1d7ae738fbdc61b7fbef14fde6a8dd945fdee07e390600c8d5657
AlienVault 4.5.0 SQL Injection
Posted Mar 31, 2014
Authored by Brandon Perry

AlienVault version 4.5.0 suffers from an authenticated remote SQL injection vulnerability. Metasploit module proof of concept is included.

tags | exploit, remote, sql injection, proof of concept
SHA-256 | 40ee4d126c36742998c3f763beb792fa2eaff2e289df522b3fa9296d803a35a6
PhotoWIFI Lite 1.0 Command Injection / LFI / File Upload
Posted Mar 31, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

PhotoWIFI Lite version 1.0 for iOS suffers from command injection, local file inclusion, and remote file upload vulnerabilities.

tags | exploit, remote, local, vulnerability, file inclusion, file upload
systems | apple, ios
SHA-256 | 9359a3d21802973d03730bfc312fb55fed478a1b39122f4166292c87c4f0dd57
Primo CMS 6.2 Remote Command Execution
Posted Mar 31, 2014
Authored by Felipe Andrian Peixoto

Primo CMS version 6.2 suffers from a remote command injection vulnerability.

tags | exploit, remote
SHA-256 | f990681225f7a22b115820d8c6849ce605618fbcd204bdfafd97a632de467801
Horde Webmail 5.1 Open Redirect
Posted Mar 31, 2014
Authored by Felipe Andrian Peixoto

Horde Webmail version 5.1 suffers from an open redirection vulnerability.

tags | exploit
SHA-256 | f3bfdd6bd23da3ad823bbc2c0e6dd878f8671a1ae58971fcb65267ec1cb64052
WordPress Js-Multi-Hotel 2.2.1 XSS / DoS / Disclosure / Abuse
Posted Mar 31, 2014
Authored by MustLive

WordPress Js-Multi-Hotel plugin version 2.2.1 suffers from cross site scripting, abuse of functionality, denial of service, and path disclosure vulnerabilities.

tags | exploit, denial of service, vulnerability, xss
SHA-256 | b0710350332e42b116bfa62641fb48da142ad7b2686b5d41ac322c55648e6fbf
AudioCoder 0.8.29 Memory Corruption
Posted Mar 31, 2014
Authored by sajith

AudioCoder version 0.8.29 memory corruption to code execution via SEH exploit.

tags | exploit, code execution
SHA-256 | 0f1d5e9ac2a09a11a1cf2de974edcdd6ae678079675b1f5f5aca4fa2fa9c1130
Fitnesse Wiki Remote Command Execution
Posted Mar 28, 2014
Authored by Veerendra G.G, Jerzy Kramarz | Site metasploit.com

This Metasploit module exploits a vulnerability found in Fitnesse Wiki, version 20140201 and earlier.

tags | exploit
advisories | CVE-2014-1216
SHA-256 | ea5185af9eacbf5f8ba32b49f0b348feaf5aeb8b06d576421ac1861e3bd61b62
SePortal 2.5 SQL Injection / Remote Code Execution
Posted Mar 28, 2014
Authored by xistence, jsass | Site metasploit.com

This Metasploit module exploits a vulnerability found in SePortal version 2.5. When logging in as any non-admin user, it's possible to retrieve the admin session from the database through SQL injection. The SQL injection vulnerability exists in the "staticpages.php" page. This hash can be used to take over the admin user session. After logging in, the "/admin/downloads.php" page will be used to upload arbitrary code.

tags | exploit, arbitrary, php, sql injection
advisories | CVE-2008-5191, OSVDB-46567
SHA-256 | 523ae89437abd95ee2b8adbfe4b6eb79e71f45e8218d4bcec51f35af6aab99d6
Ajax Pagination 1.1 Local File Inclusion
Posted Mar 28, 2014
Authored by Glyn Wintle

Ajax Pagination version 1.1 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 69e08cc5d2ea4848004a83b725d70d5539504575928edebeba5a13590e8b2878
iStArtApp FileXChange 6.2 Command Injection / LFI / File Upload
Posted Mar 28, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

iStArtApp FileXChange version 6.2 for iOS suffers from command injection, local file inclusion, and remote shell upload vulnerabilities.

tags | exploit, remote, shell, local, vulnerability, file inclusion
systems | ios
SHA-256 | 8b098835b2928b1e01d165f8e8bde1efd4aab6d93048b1a9c54783e43ca561bf
WordPress HTML Sitemap 1.2 Cross Site Request Forgery
Posted Mar 28, 2014
Authored by Tom Adams

WordPress HTML Sitemap version 1.2 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 201994735e80fa917f6e5059cc2ed56952c108819c09e3f473ea49a528417d57
GD Star Rating 1.9.22 XSS / CSRF / SQL Injection
Posted Mar 28, 2014
Authored by Tom Adams

GD Star Rating version 1.9.22 suffers from cross site request forgery, cross site scripting, and remote blind SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, csrf
SHA-256 | 796f545fbb705c4802204cc3c44a1363749e626b8c4b713647a53112da55d889
Canon PIXMA MX722 Printer Wireless Password Disclosure
Posted Mar 28, 2014
Authored by Taylor Hornby

Canon PIXMA MX722 printer suffers from a WiFi password disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 053f0b5c3da36eac0eb319318f27ed23717cee605d73853ff649d554743a60d9
WordPress Business Intelligence 1.0.6 Shell Upload
Posted Mar 28, 2014
Authored by Manish Tanwar

WordPress wp-business-intelligence plugin version 1.0.6 suffers from a remote shell upload vulnerability due to including ofc_upload_image.php.

tags | exploit, remote, shell, php
SHA-256 | cfc6ca57ddaae7ce436b3f1dd3b109d8d363bf14d5bbb4a97697b3c2cec8fbff
ASP-Nuke 2.0.7 Open Redirect
Posted Mar 28, 2014
Authored by Felipe Andrian Peixoto

ASP-Nuke version 2.0.7 suffers from an open redirect vulnerability.

tags | exploit, asp
SHA-256 | 902da011bf746423d5b241e17da52bd86559dbc0d84acce478a7761e2d717453
rexx Recruitment Cross Site Scripting
Posted Mar 27, 2014
Site redteam-pentesting.de

RedTeam Pentesting discovered a cross site scripting vulnerability in rexx Recruitment's user registration page during a penetration test. If attackers can persuade users to click on a prepared link or redirected them to such a link from an attacker-controlled website, they are able to run arbitrary JavaScript code in the context of the rexx Recruitment installation's domain.

tags | exploit, arbitrary, javascript, xss
advisories | CVE-2014-1224
SHA-256 | 2b99dd93bd3ef7fa35d56eedd30ce42a17be27a43d0080a86eaa47f243c72d0b
ePhone Disk 1.0.2 LFI / Command Injection / DoS
Posted Mar 27, 2014
Authored by LariX4, Vulnerability Laboratory | Site vulnerability-lab.com

ePhone Disk version 1.0.2 for iOS suffers from denial of service, command injection, and local file inclusion vulnerabilities.

tags | exploit, denial of service, local, vulnerability, file inclusion
systems | apple, ios
SHA-256 | 876448f07c5c05553462fd3177290aada26c9cd5919baeae2680fd062cfff2f7
Easy FileManager 1.1 Local File Inclusion / Shell Upload
Posted Mar 27, 2014
Authored by Katharina S.L., Vulnerability Laboratory | Site vulnerability-lab.com

Easy FileManager version 1.1 for iOS suffers from local file inclusion and remote shell upload vulnerabilities.

tags | exploit, remote, shell, local, vulnerability, file inclusion
systems | apple, ios
SHA-256 | 4b5d69b0cae3c7cd9e89f17f629e2e25283338e269c0c4155401deba8739d35b
Joomla Kunena 3.0.4 Cross Site Scripting
Posted Mar 27, 2014
Authored by Qoppa

Joomla Kunena component version 3.0.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 5824c2fb1d088d434657130d4759d89055357306437bfbb01644799d4d520267
My Photo Wifi Share & PS 1.1 Command Injection
Posted Mar 27, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

My Photo Wifi Share & PS 1.1 for iOS suffers from a local command injection vulnerability.

tags | exploit, local
systems | apple, ios
SHA-256 | e53e7d5c9f0ee9f794d19da2f54e4d471361b0256775259c8d71dc2f551e08df
Lazybone Studios WiFi Music 1.0 LFI / Upload
Posted Mar 27, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Lazybone Studios WiFi Music 1.0 for iOS suffers from local file inclusion and remote shell upload vulnerabilities.

tags | exploit, remote, shell, local, vulnerability, file inclusion
systems | apple, ios
SHA-256 | 11ad45715114d7c206751facff6d0a7e57d0ce6d720031cf785b958467b939ed
Page 1 of 9
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close