what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 147 RSS Feed

Files

Accellion Secure File Transfer Code Execution
Posted May 27, 2014
Authored by Thomas Hibbert | Site security-assessment.com

The Accellion Secure File Transfer SFTP Satellite ships with SSH tunneling enabled. An authorized SFTP user can connect to the SFTP satellite and leverage the SSH tunneling functionality to attack localhost bound ports that are not intended to be exposed externally. By leveraging trust assumptions in the running Rsync daemon, sensitive files including the MySQL root password are retrievable. This password can be used when connecting to the MySQL database, also running on localhost, and the password hashes of all users configured on the server can be retrieved. Accellion released a software update to version FTA_9_8_70 on the 4th of December 2013 which disables SSH tunneling and prevents this issue being exploited.

tags | exploit, root
SHA-256 | 68bc250d8823491080a18930f81edf603898e7a112a41ce582d30e72238a43bb
Splunk 6.1.1 Cross Site Scripting
Posted May 27, 2014
Authored by Asheesh Kumar Mani Tripathi

Splunk version 6.1.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 7a31ef4fcee869912b77477df42034cdbbb008b74b988e45e6ecd10d53c1f5cc
reg.ebay.com Cross Site Scripting
Posted May 26, 2014
Authored by Stefan Schurtz

reg.ebay.com suffered from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2bce10c659480dadfc71d35f3d359939f8c6abe9c02b2c900470d1756ad5480c
Core FTP Server 1.2 Build 535 Denial Of Service
Posted May 25, 2014
Authored by Kaczinski Ramirez

Core FTP Server version 1.2 build 535 32-bit crash proof of concept exploit.

tags | exploit, denial of service, proof of concept
SHA-256 | 718dbfa32e780909200eb23f74090ac03f5b7d3cf73928a385d99d0e67a07917
PHP-Nuke 8.3 News SQL Injection
Posted May 24, 2014
Authored by ali ahmady

The News module in PHP-Nuke version 8.3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
SHA-256 | a3dcb3ff99610710137c524c5160bb879d6fde1d17ff511a654c9f5276aa57e5
D-Link Cross Site Scripting / Information Disclosure
Posted May 22, 2014
Authored by Kyle Lovett

D-Link DIR-652, DIR-835, DIR-855L, DGL-500, and DHP-1565 suffer from clear text storage of passwords, cross site scripting, and sensitive information disclosure vulnerabilities.

tags | exploit, vulnerability, xss, info disclosure
SHA-256 | a7668e84297d67c97f777a5d017f21ef288453a895bebdf304e432fe59637710
Dotclear Media Manager Authenticated Arbitrary File Upload
Posted May 22, 2014
Authored by EgiX, Brandon Perry | Site metasploit.com

This is a Metasploit modules that leverages an authenticated arbitrary file upload vulnerability in Dotclear versions 2.6.2 and below.

tags | exploit, arbitrary, file upload
SHA-256 | fa7134cec4517d630b5ea12c4242fbfc9bfb06e0df1b252b0e24e5fa245675a6
WordPress Conversion Ninja Cross Site Scripting
Posted May 22, 2014
Authored by Ashiyane Digital Security Team

WordPress Conversion Ninja plugin suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, xss
SHA-256 | 0bfb7dbc417cfd5c7380ab708fe11a4521d81a62380978265ae01c7fb6d10f8c
WordPress bib2html 0.9.3 Cross Site Scripting
Posted May 22, 2014
Authored by Ashiyane Digital Security Team

WordPress bib2html plugin version 0.9.3 suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, xss
SHA-256 | a4eadb29a9ee0fe5cc72b51220221339d9488e699962c0abddc7b56cc660e24f
CoSoSys Endpoint Protector 4 SQL Injection / Backdoor
Posted May 22, 2014
Authored by S. Viehbock | Site sec-consult.com

CoSoSys Endpoint Protector 4 suffers from remote SQL injection, unauthenticated access, information disclosure, and backdoor vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, info disclosure
SHA-256 | ee59c852aa9ec9b54cfb17cac2c30abf6fbb5c230308e6bbdca47b9cb0f61f3e
Dotclear 2.6.2 SQL Injection
Posted May 22, 2014
Authored by EgiX | Site karmainsecurity.com

Dotclear versions 2.6.2 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2014-3783
SHA-256 | 2067441f7e53b38ccded93a55914eb552ab0546ea50c16e0ae0faf9cda833960
Dotclear 2.6.2 Arbitrary File Upload
Posted May 22, 2014
Authored by EgiX | Site karmainsecurity.com

Dotclear versions 2.6.2 and below suffer from a remote shell upload vulnerability.

tags | exploit, remote, shell
advisories | CVE-2014-3782
SHA-256 | 31ef78e04a371a4e90bcaf14ef4a3350c0869ac317a39cdbeb7a37d65897f61e
Dotclear 2.6.2 Authentication Bypass
Posted May 22, 2014
Authored by EgiX | Site karmainsecurity.com

Dotclear versions 2.6.2 and below suffer from an XML-RPC interface authentication bypass vulnerability.

tags | exploit, bypass
advisories | CVE-2014-3781
SHA-256 | 0ba9c89e27c9ba118a254a769b3bfb910bbbcfd3ba96f87cd6f39126a26f52b7
NULL Page Mitigations On Windows 8 x86
Posted May 22, 2014
Authored by Tavis Ormandy

This is a brief write up that discusses NULL page mitigations on Windows 8 and includes a piece of proof of concept code.

tags | exploit, proof of concept
systems | linux, windows
SHA-256 | a7d45dd13990e785f7ee6bbec647ae6693fc0348799ef70a34911098b0fb2da6
Binatone DT 850W Router Cross Site Request Forgery
Posted May 22, 2014
Authored by Samandeep Singh

Binatone DT 850W wireless router suffers from multiple cross site request forgery vulnerabilities.

tags | exploit, vulnerability, csrf
SHA-256 | 8d9c3eeed475845a253f821c47a2ce2c767601f741f279d533f68fce54e765dc
Easy Address Book Web Server 1.6 Buffer Overflow
Posted May 22, 2014
Authored by superkojiman

Easy Address Book Web Server version 1.6 suffers from a stack buffer overflow vulnerability.

tags | exploit, web, overflow
SHA-256 | eb3749421af48dd72ae5531d12a661999239e19e1c8b9971b9aeb7d94178bfa8
Easy File Management Web Server 5.3 Buffer Overflow
Posted May 22, 2014
Authored by superkojiman

Easy File Management Web Server version 5.3 suffers from a stack buffer overflow vulnerability.

tags | exploit, web, overflow
SHA-256 | 01960135cf899303cf1fae8be238f11e79604d56f7f20d97c009897fa7e524b9
Web Terra 1.1 Remote Command Execution
Posted May 22, 2014
Authored by Felipe Andrian Peixoto

Web Terra version 1.1 suffers from a remote command execution vulnerability in books.cgi. Note that this finding houses site-specific data.

tags | exploit, remote, web, cgi
SHA-256 | 2eea2813384c03daef38cb12e58fd3f3705c6955ae3cf743c539dca6cd3c4575
WordPress Booking System SQL Injection
Posted May 22, 2014
Authored by maodun

WordPress Booking System (Booking Calendar) plugin versions prior to 1.3 suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2014-3210
SHA-256 | 560cfabaaf99cea066648aa76f26ae607e277548fb3dcb5c30e5c6a8952a701f
WordPress Simple Popup Cross Site Scripting
Posted May 22, 2014
Authored by Ashiyane Digital Security Team

WordPress Simple Popup plugin suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, xss
SHA-256 | 8e827ce27070a9e0bfe5c5c3687047b5aa71caeccf9f16b658eb69634b193ce5
BSS Continuity CMS 4.2.22640.0 SQL Injection
Posted May 21, 2014
Authored by Jerzy Kramarz

BSS Continuity CMS version 4.2.22640.0 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2014-3446
SHA-256 | 43feb3cbd99eaefa88765c3c9103eabad8285af84513ee137eec680d6360a86e
BSS Continuity CMS 4.2.22640.0 Code Execution
Posted May 21, 2014
Authored by Jerzy Kramarz

BSS Continuity CMS version 4.2.22640.0 suffers from a remote code execution vulnerability via an unauthenticated file upload.

tags | exploit, remote, code execution, file upload
advisories | CVE-2014-3448
SHA-256 | f64096d831fab8b5daddf9da0cef7ef566ab842ef369e375cbf0cbd1cc51fd22
BSS Continuity CMS 4.2.22640.0 Authentication Bypass
Posted May 21, 2014
Authored by Jerzy Kramarz

BSS Continuity CMS version4.2.22640.0 suffers from a direct access bypass vulnerability.

tags | exploit, bypass
advisories | CVE-2014-3449
SHA-256 | e3ab30109477b8b881798256ebec26615cccca5ae9a61b5ba335a7b9e3e124c4
DIR-605L Disclosure / Bypass
Posted May 21, 2014
Authored by laalaa

DIR-605L suffers from password disclosure and authentication bypass vulnerabilities.

tags | exploit, vulnerability, bypass, info disclosure
SHA-256 | 34ebc0a7494b884a027be858fbef805a053014d262af42c2fac420268583749f
Artikel CMS Cross Site Scripting
Posted May 21, 2014
Authored by Renzi

Artikel CMS suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, xss
SHA-256 | 29b2e71cf0e6d4b0890cf06eccdc9b57dff712a333e877aaf3ad3f221e394afe
Page 2 of 6
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close