what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 254 RSS Feed

Files

FLIR Systems FLIR Thermal Camera F/FC/PT/D Multiple Information Disclosures
Posted Sep 25, 2017
Authored by LiquidWorm | Site zeroscience.mk

FLIP Systems thermal cameras have an issues where Input passed through several parameters is not properly verified before being used to read files. This can be exploited by an unauthenticated attacker to read arbitrary files from local resources.

tags | exploit, arbitrary, local
SHA-256 | d34a3f62ad7186d8f7f078fd8eb7e91db95aa1f3f1268a975bd96226e024248f
FLIR Systems FLIR Thermal Camera PT-Series (PT-334 200562) Remote Root
Posted Sep 25, 2017
Authored by LiquidWorm | Site zeroscience.mk

FLIR Camera PT-Series suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exist due to several POST parameters in controllerFlirSystem.php script when calling the execFlirSystem() function not being sanitized when using the shell_exec() PHP function while updating the network settings on the affected device. This allows the attacker to execute arbitrary system commands as the root user and bypass access controls in place.

tags | exploit, remote, arbitrary, root, php, vulnerability
SHA-256 | 467a838bbb50091c18ff3f7378b6872b6baa6ae7cf973e758610e0c2230ab17a
FLIR Systems FLIR Thermal Camera FC-S/PT Authenticated OS Command Injection
Posted Sep 25, 2017
Authored by LiquidWorm | Site zeroscience.mk

FLIR FC-S/PT series suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user.

tags | exploit, arbitrary, shell, root
SHA-256 | 72dca7a2b36694be2eb020a1a8df5c0c7188a5b47584564c2c6a6f0a692581b1
Supervisor XML-RPC Authenticated Remote Code Execution
Posted Sep 25, 2017
Authored by Calum Hutton | Site metasploit.com

This Metasploit module exploits a vulnerability in the Supervisor process control software, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. Depending on how supervisord has been configured, this may be root. This vulnerability can only be exploited by an authenticated client, or if supervisord has been configured to run an HTTP server without authentication. This vulnerability affects versions 3.0a1 to 3.3.2.

tags | exploit, web, arbitrary, shell, root
advisories | CVE-2017-11610
SHA-256 | 99930294bef23f9b9d84c06aa2386d0ad63e5b162e9d0bb0cd32b041027c9f56
BlueBorne BlueTooth Buffer Overflow Proof Of Concept
Posted Sep 25, 2017
Authored by Marcin Kozlowski

BlueBorne BlueTooth buffer overflow proof of concept exploit that causes a denial of service vulnerability on Linux kernels prior to 4.13.1.

tags | exploit, denial of service, overflow, kernel, proof of concept
systems | linux
advisories | CVE-2017-1000251
SHA-256 | 974f187dadca11aa8a6672fa308652e8c4e301f2e239dcd9ebe671ec208a6e34
Kaltura 13.1.0 Code Execution / Cross Site Scripting
Posted Sep 23, 2017
Authored by Robin Verton

Kaltura versions 13.1.0 and below suffer from code execution and cross site scripting vulnerabilities.

tags | exploit, vulnerability, code execution, xss
advisories | CVE-2017-14141, CVE-2017-14142, CVE-2017-14143
SHA-256 | f13d7e1066f62d0ca0b0da505366a1d539c7943e2d61a9efc629ec92d9a34e9f
DenyAll Web Application Firewall Remote Code Execution
Posted Sep 23, 2017
Authored by Mehmet Ince | Site metasploit.com

This Metasploit module exploits the command injection vulnerability of DenyAll Web Application Firewall. Unauthenticated users can execute a terminal command under the context of the web server user.

tags | exploit, web
SHA-256 | e5643fffa4297f5d5b48f257e93c3396e073c9df8c778d9d0abdbed89abcab11
PHP Auction Ecommerce Script 1.6 SQL Injection
Posted Sep 22, 2017
Authored by 8bitsec

PHP Auction Ecommerce Script version 1.6 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
SHA-256 | e11d8ca751f12ac904f6ae849f6b00120b49672fedb040237069b33d271e6638
Cash Back Comparison Script 1.0 SQL Injection
Posted Sep 22, 2017
Authored by Ihsan Sencan

Cash Back Comparison Script version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | bf0129d1568c533f775662e94d71b60428120c4f89f7a7f646d79d5008c48602
Secure E-Commerce Script 1.02 SQL Injection
Posted Sep 22, 2017
Authored by 8bitsec

Secure E-Commerce Script version 1.02 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 6ecc8f905e6696e16dc6fc46ccfddf32a1e6d43f347350788a2966842018b964
Claydip Airbnb Clone 1.0 Arbitrary File Upload
Posted Sep 22, 2017
Authored by Ihsan Sencan

Claydip Airbnb Clone version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | d394625cf6d56283ba1e531eb76ad82163659e54c6b79be35985e65e1c838577
Lending And Borrowing SQL Injection
Posted Sep 22, 2017
Authored by Ihsan Sencan

Lending and Borrowing suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | a5f2aae02d2fa6420f4bf2e171e91c57bc8d1a3ca3e87c483fefbf51a27aea54
Multi Level Marketing SQL Injection
Posted Sep 22, 2017
Authored by Ihsan Sencan

Multi Level Marketing suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 227e8fbe62124c42fae50d8152fbcb9c2d4464daad8b6a50d9af4854d13e399e
Microsoft Edge Chakra JavascriptFunction::ReparseAsmJsModule Parsing Issue
Posted Sep 22, 2017
Authored by Google Security Research, lokihardt

Microsoft Edge Chakra JavascriptFunction::ReparseAsmJsModule suffers from a parsing issue.

tags | exploit
advisories | CVE-2017-8755
SHA-256 | 04786d716e5bbc515fcb82e70cc835c336e1f9a711c6bd4916ec298d728b059c
Microsoft Edge Chakra Parser::ParseCatch Failed eval Handle
Posted Sep 22, 2017
Authored by Google Security Research, lokihardt

Microsoft Edge Chakra Parser::ParseCatch fail to handle eval properly.

tags | exploit
advisories | CVE-2017-11764
SHA-256 | ab4355edeff5bc32a4c78094cc0d6544b969b096f7f75973839307d64d3834c7
Microsoft Edge Charka Wrong Scopes In Deferred Parsing
Posted Sep 22, 2017
Authored by Google Security Research, lokihardt

Microsoft Edge Chakra makes wrong scopes in deferred parsing.

tags | exploit
advisories | CVE-2017-8740
SHA-256 | 46c5852cffb12bf17caf6302d304337fc43055946fa9a608bd1dce0284336d11
Microsoft Edge Chakra Incorrect Parse
Posted Sep 22, 2017
Authored by Google Security Research, lokihardt

Microsoft Edge Charka incorrectly parses object patterns.

tags | exploit
advisories | CVE-2017-8729
SHA-256 | 861d591b479ea3ed6c0ad8fd09bf8f8400adee9fdab27742f1cf3812afe1c4dc
phpMyFAQ 2.9.8 Cross Site Scripting
Posted Sep 21, 2017
Authored by Ishaq Mohammed

phpMyFAQ version 2.9.8 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2017-14618
SHA-256 | 341b845511d328e01e97ed403a18ff1aabc3cd35bc0e0eea9412ac77ac089f2f
WordPress Responsive Image Gallery 1.1.8 SQL Injection
Posted Sep 21, 2017
Authored by Manuel Garcia Cardenas

WordPress Responsive Image Gallery plugin version 1.1.8 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2017-14125
SHA-256 | 5d6d5bc59c4b6c46cabe5218a99c3da34389ba51b7860a91a33705fcbb5eda0b
Disk Pulse Enterprise 9.9.16 GET Buffer Overflow
Posted Sep 21, 2017
Authored by Nipun Jaswal, Chance Johnson, Anurag Srivastava | Site metasploit.com

This Metasploit module exploits an SEH buffer overflow in Disk Pulse Enterprise version 9.9.16. If a malicious user sends a crafted HTTP GET request it is possible to execute a payload that would run under the Windows NT AUTHORITY\SYSTEM account.

tags | exploit, web, overflow
systems | windows
SHA-256 | 876a9a5d808b0659fa59d564a70173b778f43b52723877c001da3267e7263ec7
Mongoose Embedded Web Server Library 6.8 Buffer Overflow
Posted Sep 20, 2017
Authored by Dobin Rutishauser

Mongoose Embedded Web Server Library versions 6.8 and below suffer from a stack-based buffer overflow vulnerability.

tags | exploit, web, overflow
SHA-256 | 4fb80ad189731d24ec26827f09996fc6817ecce4f5d42ff3a887ceacbec10d9b
Pixie Image Editor 1.7 Server-Side Request Forgery
Posted Sep 20, 2017
Authored by BeiJing Baimaohui Technology Co., LTD.

Pixie Image Editor versions 1.4 and 1.7 suffer from a server-side request forgery vulnerability.

tags | exploit
advisories | CVE-2017-12905
SHA-256 | 4810929f8c991ac10100bb073270d0ab4cae3ded5c49e3be1cd7403684da5f73
WordPress 2kb Amazon Affiliates Store 2.1.0 Cross Site Scripting
Posted Sep 20, 2017
Authored by Ricardo Sanchez

WordPress 2kb Amazon Affiliates Store plugin versions 2.1.0 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3ae51e465aa8a2ee5523c26071aa889af6b47942e855e9e601be39a1530278ee
SUSE/Portus 2.2 Cross Site Scripting
Posted Sep 19, 2017
Authored by Ricardo Sanchez

SUSE/Portus version 2.2 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
systems | linux, suse
SHA-256 | 0f89be3598b185b26e1d2346f6a7fe4fee3bd2aa160be8583d7a7b5cb67d1258
DlxSpot Hardcoded Password
Posted Sep 19, 2017
Authored by Simon Brannstrom

DlxSpot Player4 LED video wall has a hardcoded password that allows you to ssh in and escalate to root.

tags | exploit, root
advisories | CVE-2017-12928, CVE-2017-12929, CVE-2017-12930
SHA-256 | ad7221803cc82d07c5c7cb36a0c7fa5ab1c1470b7d79822c80ae2cf2222c91ef
Page 4 of 11
Back23456Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close