exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 179 RSS Feed

Files

Joomla Huge-IT Video Gallery 1.0.9 SQL Injection
Posted Sep 22, 2016
Authored by Larry W. Cashdollar

Joomla Huge-IT Video Gallery component version 1.0.9 suffers from a remote unauthenticated SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2016-1000123
SHA-256 | 23591d1c5baab1dd97cf541e0e9530809619db9d2680fd8d0aa19ddcb03cd816
Kerio Control Unified Threat Management Code Execution / XSS / Memory Corruption
Posted Sep 22, 2016
Authored by Rene Freingruber, Raschin Tavakoli | Site sec-consult.com

Kerio Control Unified Threat Management versions prior to 9.1.3 suffer from unsafe usage of the PHP unserialize function, code execution, memory corruption, cross site scripting, and various other vulnerabilities.

tags | exploit, php, vulnerability, code execution, xss
SHA-256 | c22171b8824d2b252b1a4ea012d4bc8d7cc2305a401acabe53ffb1f9885c3e3d
Microsoft Internet Explorer 11 CORS Disrespect
Posted Sep 22, 2016
Authored by Ricardo Iramar dos Santos

Microsoft Internet Explorer 11 is not following the CORS specification for local files like Chrome and Firefox. Microsoft does not believe this to be a security issue.

tags | exploit, local
SHA-256 | d427f830f768b41cde9f338a6e270c5ffdd96617add1cdcfb86beb27d8769480
Silverstripe Theme Newedge Cross Site Scripting
Posted Sep 22, 2016
Authored by ZwX

Silverstripe theme Newedge suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2ad7428ab78125654bb9ea68b2d4509003baf6277ff46bf667722791a214f490
Kaltura Remote PHP Code Execution
Posted Sep 22, 2016
Authored by Mehmet Ince | Site metasploit.com

This Metasploit module exploits an Object Injection vulnerability in Kaltura. By exploiting this vulnerability, unauthenticated users can execute arbitrary code under the context of the web server user. Kaltura has a module named keditorservices that takes user input and then uses it as an unserialized function parameter. The constructed object is based on the SektionEins Zend code execution POP chain PoC, with a minor modification to ensure Kaltura processes it and the Zend_Log function's __destruct() method is called. Kaltura versions prior to 11.1.0-2 are affected by this issue. This Metasploit module was tested against Kaltura 11.1.0 installed on CentOS 6.8.

tags | exploit, web, arbitrary, code execution
systems | linux, centos
SHA-256 | ba9012dd4f49aefcf4379514160c82dc80f1785189dc8f95974035d6f73830f1
Metasploit Web UI Diagnostic Console Command Execution
Posted Sep 22, 2016
Authored by Justin Steven | Site metasploit.com

This Metasploit module exploits the "diagnostic console" feature in the Metasploit Web UI to obtain a reverse shell. The diagnostic console is able to be enabled or disabled by an administrator on Metasploit Pro and by an authenticated user on Metasploit Express and Metasploit Community. When enabled, the diagnostic console provides access to msfconsole via the web interface. An authenticated user can then use the console to execute shell commands. NOTE: Valid credentials are required for this module. Tested against: Metasploit Community 4.1.0, Metasploit Community 4.8.2, Metasploit Community 4.12.0

tags | exploit, web, shell
SHA-256 | 4f3bb48177d573f2d188fe4a2e93543cd54f1257e65865784c469730b1b9051b
BT Wifi Extenders 300 / 600 / 1200 Cross Site Scripting
Posted Sep 22, 2016
Authored by Jamie Riden

BT Wifi Extenders models 300, 600, and 1200 suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 83936b94e6a31c5e450025084893cfe0398ef6c6e6db76f38eb0bae5f21ba3f2
jsch 0.1.53 Path Traversal
Posted Sep 21, 2016
Authored by oststrom

A malicious sftp server may force a client-side relative path traversal in jsch's implementation for recursive sftp-get allowing the server to write files outside the clients download basedir with effective permissions of the jsch sftp client process. Versions 0.1.53 and below are affected.

tags | exploit
advisories | CVE-2016-5725
SHA-256 | dfd3deafc8949119431558bc8219895f763a1d7d6a7b008eccb812e5d19ba8c3
Symantec Outdated RAR Decomposer
Posted Sep 21, 2016
Authored by Tavis Ormandy, Google Security Research

Symantec Antivirus includes RAR unpacking memory corruption issues that can lead to remote code execution.

tags | exploit, remote, code execution
SHA-256 | 9f57b2a3b52264e8df535a836560985566bdee33f433a00744602c523418b41f
Microsoft Office PowerPoint 2010 Invalid Pointer Reference
Posted Sep 21, 2016
Authored by Google Security Research, scvitti

Microsoft PowerPoint 2010 suffers from an invalid pointer dereference vulnerability.

tags | exploit
advisories | CVE-2016-3357
SHA-256 | 5c7cd7d8e99b6f1f1a0d9fbb154e1948a7c293749f6d7b8665e48d59d78f8193
WordPress W3 Total Cache 0.9.4.1 Cross Site Scripting
Posted Sep 21, 2016
Authored by Zerial

WordPress W3 Total Cache (w3tc) plugin versions 0.9.4.1 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | fd336a5de820d4386bd67cceecd95849541d0a8251cd5a04277ce69a6823f9b8
Exponent CMS 2.3.9 Blind SQL Injection
Posted Sep 20, 2016
Authored by Manuel Garcia Cardenas

Exponent CMS versions 2.3.9 and below suffer from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2016-7400
SHA-256 | 3e237ec6c00af59c1ddbf878a77aa82dabfd991c656a7c28bd3a59c7ae1da0ed
VegaDNS 0.13.2 Remote Command Injection
Posted Sep 20, 2016
Authored by Wireghoul

VegaDNS version 0.13.2 suffers from a remote command injection vulnerability.

tags | exploit, remote
SHA-256 | 691f14f46448b114528c54e8b25a49d68c7140203e7d8634eb7318d2424b2d4a
Dolphin 7.3.0 SQL Injection
Posted Sep 20, 2016
Authored by Kacper Szurek

Dolphin version 7.3.0 suffers from an error-based remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 3f7601ff61e6c2a8e66c765afa277832197db4eb3fe1136bd295b5ff8d0e6de3
DLL Hijack Auditor 3.5 Stack Buffer Overflow
Posted Sep 20, 2016
Authored by ZwX

DLL Hijack Auditor version 3.5 suffers from a stack buffer overflow vulnerability.

tags | exploit, overflow
systems | windows
SHA-256 | 079daf2fcf5386a4fd101c08688706ca0b26eb047c680de68e2dcb012253f2f8
AppDynamic 4.3.2.1 Build 57 Cross Site Scripting
Posted Sep 20, 2016
Authored by Govind Singh

AppDynamic version 4.3.2.1 build 57 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f5cde956ddc6e0d21c9c246292f6adeeb00e7f88e875c634f3558a2a44267ec9
ZineBasic 1.1 Remote File Disclosure
Posted Sep 19, 2016
Authored by bd0rk

ZineBasic version 1.1 suffers from a file disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 06b86484883fae23c8361309d9226646bad9cb8fbabb56cbe1ca5a708ff912f7
ShoreTel Connect ONSITE Blind SQL Injection
Posted Sep 19, 2016
Authored by Iraklis Mathiopoulos

ShoreTel Connect ONSITE versions 20.xx.xxxx.x and 21.xx.xxxx.x up to 21.79.4311.0 suffer from an unauthenticated remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 5fe02891997443ded0a53a2ce816960a4a202cd2c141c914b517d4e640ef0545
EKG Gadu 1.9~pre+r2855-3+b1 Local Buffer Overflow
Posted Sep 19, 2016
Authored by Juan Sacco

EKG Gadu versions 1 through 1.9~pre+r2855-3+b1 suffer from a local buffer overflow vulnerability.

tags | exploit, overflow, local
SHA-256 | aff59676a07ff154fa771cc294cbe56e8183978dc06b3dd5415de1f85a85f11e
MetInfo 3.0 SQL Injection
Posted Sep 19, 2016
Authored by indoushka

MetInfo version 3.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 80cb6eb5667364f3286bbb37f303a6416c133be7473e6f3e36d2d33b71b91b40
CodeCanyon iBilling 2.4 Cross Site Scripting
Posted Sep 19, 2016
Authored by indoushka

CodeCanyon iBilling version 2.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | d41d9e15c4377e6843aa40aa225587fee960487ca541dcbc3aa1522e730879d7
ECShop 2.7.2 Open Redirect
Posted Sep 19, 2016
Authored by indoushka

ECShop version 2.7.2 suffers from an open redirection vulnerability.

tags | exploit
SHA-256 | e2a2b9bda2e63613dc12ca1dac19cb1a78d027e42940469e7b036872f2a9c921
Coupon CMS 5.00 Open Redirect
Posted Sep 19, 2016
Authored by indoushka

Coupon CMS version 5.00 suffers from an open redirection vulnerability.

tags | exploit
SHA-256 | 5599af4764b8c21fc79507d31150a23d50bc62d02d88da4c361685c6f38e5470
VMWare Workstation vprintproxy.exe JPEG2000 Handling Memory Corruption
Posted Sep 19, 2016
Authored by Google Security Research, mjurczyk

VMWare Workstation vprintproxy.exe suffers from multiple memory corruption and other crashes in the handling of JPEG2000 images.

tags | exploit
advisories | CVE-2016-7084
SHA-256 | edd5397d8b520f00253f4f9311dff71b9765d0e2c44fa145e57518fe92c73758
VMWare Workstation vprintproxy.exe TrueType NAME Heap Buffer Overflow
Posted Sep 19, 2016
Authored by Google Security Research, mjurczyk

VMWare Workstation vprintproxy.exe suffers from a heap buffer overflow vulnerability in the handling of TrueType NAME tables.

tags | exploit, overflow
advisories | CVE-2016-7083
SHA-256 | 1d5414c24aa6efa04b7bd1a2dd19dca752085107658d72d462362ffb0de5eceb
Page 3 of 8
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close