what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 147 RSS Feed

Files

ClassAd Cross Site Scripting
Posted May 21, 2014
Authored by Renzi

ClassAd suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, xss
SHA-256 | 02a2c0b255ff4254797f868e19ff5ad1d09521aa1ffc45f92f2aa33e8a00bbef
Flying Cart Cross Site Scripting
Posted May 21, 2014
Authored by Renzi

Sites using Flying Cart suffer from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, xss
SHA-256 | 94e71e6c1f57749ac86022d71ebb2690578d7642017877347bfa8c2e2f9cfb4e
Perseus' Java Hopper Cross Site Scripting
Posted May 20, 2014
Authored by Renzi

Perseus' Java Hopper suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.

tags | exploit, java, xss
SHA-256 | 1a952079b2e021364160e3158865b9764b672b7331c8c743654ad542bcd9340b
Symantec Workspace Streaming Arbitrary File Upload
Posted May 20, 2014
Authored by rgod, juan vazquez | Site metasploit.com

This Metasploit module exploits a code execution flaw in Symantec Workspace Streaming. The vulnerability exists in the ManagementAgentServer.putFile XMLRPC call exposed by the as_agent.exe service, which allows for uploading arbitrary files under the server root. This Metasploit module abuses the auto deploy feature in the JBoss as_ste.exe instance in order to achieve remote code execution. This Metasploit module has been tested successfully on Symantec Workspace Streaming 6.1 SP8 and Windows 2003 SP2. Abused services listen on a single machine deployment, and also in the backend role in a multiple machine deployment.

tags | exploit, remote, arbitrary, root, code execution
systems | windows
advisories | CVE-2014-1649
SHA-256 | cb1b416c6a81192072db5387c939127cc89639e3ba035c140a68125e64bbc407
AoA MP4 Converter 4.1.2 Active-X Overflow
Posted May 20, 2014
Authored by metacom

AoA MP4 Converter version 4.1.2 suffers from an overflow vulnerability.

tags | exploit, overflow, activex
SHA-256 | cd63ce9472faafdf4e2e783946b14d6f167f018ab91f2599cfb2ebd6900462a4
SafeNet Sentinel Directory Traversal
Posted May 20, 2014
Authored by Matt Schmidt

SafeNet Sentinel Protection Server versions 7.0 through 7.4 and Keys Server versions 1.0.3 through 1.0.4 suffer from a directory traversal vulnerability.

tags | exploit, file inclusion
advisories | CVE-2007-6483, OSVDB-42402
SHA-256 | 44d8d12aafec471f9f40aac23224aaabaa726ad6187322040baee9fe298880fc
Oracle JavaMail SMTP Header Injection
Posted May 20, 2014
Authored by Alexandre Herzog

JavaMail does not check if the email subject contains a Carriage Return (CR) or a Line Feed (LF) character on POST multipart requests. This issue allows the injection of arbitrary SMTP headers in the generated email. This flaw can be used for sending SPAM or other social engineering attacks (e.g. abusing a trusted server to send HTML emails with malicious content). Versions 1.4.5 and 1.5.1 were found vulnerable.

tags | exploit, arbitrary
SHA-256 | 405fd5ea751ac4705c07542a270ee08ffee8bea6e4c25464024c27431b045351
Clipperz Password Manager Code Execution
Posted May 20, 2014
Authored by Manish Tanwar

Clipperz Password Manager suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
SHA-256 | a389dff208c61b443364f2e6e4129153bf3222246ff2df01244a949c8e244afe
AoA Audio Extractor 2.3.7 Active-X Overflow
Posted May 20, 2014
Authored by metacom

AoA Audio Extractor Basic version 2.3.7 suffers from an overflow vulnerability.

tags | exploit, overflow, activex
SHA-256 | dcf9cf1e13d58871d2e0e4bc3827849243e29adbcd9d4d52281ed0f2d1705f6c
CyberLink Power2Go Essential 9.0.1002.0 Overflow
Posted May 20, 2014
Authored by Mike Czumak

CyberLink Power2Go Essential version 9.0.1002.0 suffers from a registry SEH/unicode buffer overflow vulnerability.

tags | exploit, overflow, registry
SHA-256 | c4ad3ea0e0cf296b67878e6a6773f715ce52a1c11772efc0549219c883df125a
AoA DVD Creator 2.6.2 Active-X Overflow
Posted May 20, 2014
Authored by metacom

AoA DVD Creator version 2.6.2 suffers from an overflow vulnerability.

tags | exploit, overflow, activex
SHA-256 | 2f31adef0c26503f7dcc55055e82e81b9c030906ddfc9884aac7a7f920f2863e
Seo Panel 3.4.0 Cross Site Scripting
Posted May 19, 2014
Authored by High-Tech Bridge SA | Site htbridge.com

Seo Panel version 3.4.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2014-1855
SHA-256 | a478c32cb9af5fb501f74cbb29a394595bb4f20a6926285d8f761e38231064c9
HP Release Control 9.20.0000 Build 395 XXE
Posted May 19, 2014
Authored by Brandon Perry | Site metasploit.com

This Metasploit module takes advantage of three separate vulnerabilities in order to read an arbitrary text file from the file system with the privileges of the web server. You must be authenticated, but can be unprivileged since a privilege escalation vulnerability is used. Tested against HP Release Control 9.20.0000, Build 395 installed with demo data. The first vulnerability allows an unprivileged authenticated user to list the current users, their IDs, and even their password hashes. Can't login with hashes, but the ID is useful in the second vulnerability. When a user changes their password, they post the ID of the user who is going to have their password changed. Just replace it with the admin ID and you change the admin password. You are now admin. The third vulnerability is an XXE in the dashboard XML import mechanism. This is what allows you to read the file from the file system. This Metasploit module is super ghetto half because it was an AMF application, half because I worked on it longer than I wanted to.

tags | exploit, web, arbitrary, vulnerability, xxe
SHA-256 | 32678ccb2a4454a4f3176a572bfd08436712de26dce1cdfb8b2986d281d3c14e
XOOPS Glossaire 1.0 SQL Injection
Posted May 19, 2014
Authored by AtT4CKxT3rR0r1ST

XOOPS module Glossaire version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | a4470aa99ea11a5f9c282b6f993f8063c3a3288f96bffe613ee69ced409f8c79
Wiser 2.10 Backup Disclosure
Posted May 19, 2014
Authored by AtT4CKxT3rR0r1ST

Wiser version 2.10 suffers from a backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | c26e09ae50d4b608b25cd47bc4c0eb2709de37db147ba812378aa9348bd8f835
SMART iPBX SQL injection
Posted May 19, 2014
Authored by AtT4CKxT3rR0r1ST

SMART iPBX suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 0e228b7ec6d89267b0aca22b0aae4fd724817db1d8173289e79cab2dafe203a9
SIP Server By Kerne.org SQL Injection / Backup Disclosure
Posted May 19, 2014
Authored by AtT4CKxT3rR0r1ST

SIP Server by Kerne.org suffers from remote SQL injection and backup disclosure vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | fe39892f12c45c5cbcc5327efd59baceaf7617936f8dda149687a54792646c31
PHP-Nuke Web Links SQL Injection
Posted May 19, 2014
Authored by AtT4CKxT3rR0r1ST

PHP-Nuke Web Links suffers from a remote SQL injection vulnerability.

tags | exploit, remote, web, php, sql injection
SHA-256 | 7d294df4f893166c5d430655e923ffacdae294f6c98718bca8371ebefc94493a
CRMAPP SQL Injection
Posted May 19, 2014
Authored by AtT4CKxT3rR0r1ST

CRMAPP suffers from a time-based remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7a1d6906587fbf34c99caa70266be93714a76f56d009b6016009ad37a07574e3
Construtiva CIS Manager SQL Injection
Posted May 18, 2014
Authored by Thiago C.

Construtiva CIS Manager suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2014-3749
SHA-256 | 7136c76d7db570fc9ac688d69aeeca0d8846c1171cdc6199197d0dcc66015ca5
Nagios Plugins 2.0.1 check_dhcp Arbitrary File Read
Posted May 18, 2014
Authored by Dawid Golunski

Nagios Plugins versions 2.0.1 and below suffer from an arbitrary file read vulnerability via check_dhcp.

tags | exploit, arbitrary
SHA-256 | 06b295d336a8c90eb6729752963778c1daffd50f2c930f399a48e00d05704d46
WordPress cnhk-slideshow Shell Upload
Posted May 18, 2014
Authored by Ashiyane Digital Security Team

WordPress cnhk-slideshow plugin suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 559f24d812b08368e3f3bc3029d3d487db79d8b401ebfa988c6541b0381bdef4
UPS Web/SNMP-Manager CS121 Login Bypass
Posted May 17, 2014
Authored by jkmac

UPS Web/SNMP-Manager CS121 by Generex comes in with a default enabled "service"-port, that makes it possible to bypass any specified login for HTTP(s), snmp or telnet.

tags | exploit, web
SHA-256 | 4bd1c3577ab09b7e5e33f32952b9014f9f0a435701fd9a44164f65c1033552a0
BarracudaDrive 6.7.2 Cross Site Scripting
Posted May 16, 2014
Authored by Manish Tanwar

BarracudaDrive version 6.7.2 suffers from multiple reflective and persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | d41472b73eb1e68306169abb69831256e5000c2d91afe4d895f79081b2bd8cb6
EGroupware 1.8.006 Cross Site Request Forgery / Code Injection
Posted May 16, 2014
Authored by High-Tech Bridge SA | Site htbridge.com

EGroupware version 1.8.006 suffers from code execution and cross site request forgery vulnerabilities.

tags | exploit, vulnerability, code execution, file inclusion, csrf
advisories | CVE-2014-2987, CVE-2014-2988
SHA-256 | 7d08464cab77afb7f22daf9c5a982166be13306330e34cbf9aa49130bbce7d96
Page 3 of 6
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close