exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 163 RSS Feed

Files

Packet Storm New Exploits For April, 2021
Posted May 1, 2021
Authored by Todd J. | Site packetstormsecurity.com

This archive contains all of the 162 exploits added to Packet Storm in April, 2021.

tags | exploit
SHA-256 | a04091e61e7839d1a4c9159b51aa7cde9468bc893b095e74d64c17a04a96714a
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
Posted Apr 30, 2021
Authored by Pedro Ribeiro | Site metasploit.com

This Metasploit module exploits a command injection vulnerability on login that affects Micro Focus Operations Bridge Reporter on Linux, versions 10.40 and below. It is a straight up command injection, with little escaping required, and it works before authentication. This module has been tested on the Linux 10.40 version.

tags | exploit
systems | linux
advisories | CVE-2021-22502
SHA-256 | 86c50279de70c09dd3d6cb11b4b245b4e8b6b272a33434965e6bc86812dced42
Micro Focus Operations Bridge Reporter shrboadmin Default Password
Posted Apr 30, 2021
Authored by Pedro Ribeiro | Site metasploit.com

This Metasploit module abuses a known default password on Micro Focus Operations Bridge Reporter. The shrboadmin user, installed by default by the product has the password of shrboadmin, and allows an attacker to login to the server via SSH. This module has been tested with Micro Focus Operations Bridge Manager 10.40. Earlier versions are most likely affected too. Note that this is only exploitable in Linux installations.

tags | exploit
systems | linux
advisories | CVE-2020-11857
SHA-256 | f916dce1d07e07e927e2802d2dca83cb6a07b9d397ca34c5d01f9b2245b2667b
OX App Suite / OX Guard SSRF / DoS / Cross Site Scripting
Posted Apr 30, 2021
Authored by Martin Heiland

OX App Suite versions 7.10.4 and below suffer from cross site scripting and server-side request forgery vulnerabilities. OX Guard versions 2.10.4 and below suffer from a denial of service vulnerability.

tags | exploit, denial of service, vulnerability, xss
advisories | CVE-2020-28943, CVE-2020-28944, CVE-2020-28945
SHA-256 | f79fdb3de2e0adf5d96f8bd0f53e9ea78572bc1ad06052cccf66726ab09192b0
Piwigo 11.3.0 SQL Injection
Posted Apr 30, 2021
Authored by nu11secur1ty

Piwigo version 11.3.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2021-27973
SHA-256 | 533a62f1f8e0052145c4e4a3cc6e36248076593a3246e51e8c573ba2c3b42ec6
Backdoor.Win32.Agent.oj MVID-2021-0197 Code Execution
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.oj malware suffers from a code execution vulnerability.

tags | exploit, code execution
systems | windows
SHA-256 | 8faeac759a05bb08486eda151fb354844f5f6baa709ab533fa8a32f7f70b7ef7
Microsoft Windows UAC Privilege Escalation
Posted Apr 30, 2021
Authored by Stefan Kanthak

Microsoft Windows can dupe users into trusting executables with DLL hijacking and privilege escalation issues.

tags | exploit
systems | windows
SHA-256 | cb269dbc3308c3e9fbe0001388d76caee981689af8bcb73404441bdd457de392
Backdoor.Win32.Agent.oj MVID-2021-0196 Buffer Overflow
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.oj malware suffers from a buffer overflow vulnerability.

tags | exploit, overflow
systems | windows
SHA-256 | 8c8a79c42d3684955728d6f7686bdbb095f8f13153149e1a27e1a6280de557d0
Moodle 3.6.1 Cross Site Scripting
Posted Apr 30, 2021
Authored by farisv

Moodle version 3.6.1 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2019-3810
SHA-256 | 10b48eb14b6ab75c6cca96bf82b5960e18db998f04cd97bf856e58bca99bcedf
Backdoor.Win32.Agent.kte MVID-2021-0195 Buffer Overflow
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.kte malware suffers from a buffer overflow vulnerability.

tags | exploit, overflow
systems | windows
SHA-256 | a7887dce90da6a772b91c0867e50b61c4a1907fe63ed8b6931a5095b5e2c1906
Backdoor.Win32.Agent.gmug MVID-2021-0194 Heap Corruption
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.gmug malware suffers from a heap corruption vulnerability.

tags | exploit
systems | windows
SHA-256 | 88399c2d9a4a3ecb689286c86845703121ea80b4bbcb96466285c0b81ea351ea
GNU wget Arbitrary File Upload / Code Execution
Posted Apr 30, 2021
Authored by Dawid Golunski, liewehacksie

GNU wget versions prior to 1.1.8 arbitrary file upload and code execution exploit.

tags | exploit, arbitrary, code execution, file upload
advisories | CVE-2016-4971
SHA-256 | 9eb9c61465681cef828940670f5a66c10bc60e1ed0055a7bd92271cfbcee572f
Backdoor.Win32.Agent.ggw MVID-2021-0193 Authentication Bypass
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.ggw malware suffers from a bypass vulnerability.

tags | exploit, bypass
systems | windows
SHA-256 | c52bcc6a9c74baab8584f1ee937aab5d3bc4311b75c55a5c5958da7c12fb02b7
Worm.Win32.Delf.hu MVID-2021-0192 Insecure Permissions
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

Worm.Win32.Delf.hu malware suffers from an insecure permissions vulnerability.

tags | exploit, worm
systems | windows
SHA-256 | 6abbcbb6c16e555127af6d381336bf0beab2d7cb1f78f22cd669c983a5c78385
HEUR.Trojan.Win32.Bayrob.gen MVID-2021-0191 Insecure Permissions
Posted Apr 30, 2021
Authored by malvuln | Site malvuln.com

HEUR.Trojan.Win32.Bayrob.gen malware suffers from an insecure permissions vulnerability.

tags | exploit, trojan
systems | windows
SHA-256 | 2f480d1b3c8516a6a6b58a12b785d20764d12fcc0e8ea1277b9aadf1006ce7e6
Microsoft SAFER Bypass
Posted Apr 30, 2021
Authored by Stefan Kanthak

A new SAFER bypass was discovered that affects older versions of windows.

tags | exploit
systems | windows
SHA-256 | af2bc8f393023dfcfdbaf3b86d4f45468c9560916410eab2deed331e64585960
NodeBB Emoji 3.2.1 Arbitrary FIle Write
Posted Apr 29, 2021
Authored by 1F98D

NodeBB Emoji plugin version 3.2.1 suffers from an arbitrary file write vulnerability.

tags | exploit, arbitrary
SHA-256 | b8efb1e731fd411b0d82d14ee601854ed4c4affe7d5760b5648cf818e59afbaa
Cacti 1.2.12 SQL Injection / Remote Code Execution
Posted Apr 29, 2021
Authored by M4yFly, Leonardo Paiva

Cacti version 1.2.12 remote code execution exploit that leverages a remote SQL vulnerability.

tags | exploit, remote, code execution, sql injection
advisories | CVE-2020-14295
SHA-256 | 5599594befaf80c893938a8659f1ac8a0b62ce19e5b98e608838251275c379bd
Fog Project 1.5.9 Shell Upload
Posted Apr 29, 2021
Authored by sML

Fog Project version 1.5.9 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 7e8cccd3841e142272092a1936ee9f391365414d6ca4534f3ca93844e16d8c1b
PFSense 2.5.0 Cross Site Scripting
Posted Apr 28, 2021
Authored by William Costa

PFSense version 2.5.0 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 02b3a89e00b1d86a0f7404761e5aeb0f3dd4630b2ce7e4c2b07ba93c7ea691c7
Android NFC Stack Out-Of-Bounds Write
Posted Apr 28, 2021
Authored by Google Security Research, nedwill

Android suffers from an out-of-bounds write in the NFC stack when handling MIFARE Classic TLVs.

tags | exploit
advisories | CVE-2021-0430
SHA-256 | 95f7586d9c9572c817ae465d9365cac1a950277dfa2d9ddeb3aefcc41ac59f17
Backdoor.Win32.Agent.afq MVID-2021-0190 Heap Corruption
Posted Apr 28, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.afq malware suffers from a heap corruption vulnerability.

tags | exploit
systems | windows
SHA-256 | f46ad9d6ff8413bc6b571690fc3661a3308a61b6a2b3b6ba4da2b61e6ce40019
Backdoor.Win32.Agent.afq MVID-2021-0189 Directory Traversal
Posted Apr 28, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.afq malware suffers from a directory traversal vulnerability.

tags | exploit
systems | windows
SHA-256 | c61586efd542ab899a2ca890fdb49d1bd00571af2de1dcbeacaa29cef23b2fdf
GitHub Missing Audit Logging
Posted Apr 28, 2021
Authored by Yakov Shafranovich | Site wwws.nightwatchcybersecurity.com

Release functionality on GitHub.com allows modification of assets within a release by any project collaborator. This can occur after the release is published, and without notification or audit logging accessible in the UI to either the project owners or the public.

tags | exploit
SHA-256 | a9d09c7f970e183298b90b8052e3412ba79d05b1448bd2d0c9c5ff3dfc4ead5b
Backdoor.Win32.Agent.afq MVID-2021-0188 Missing Authentication
Posted Apr 28, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.afq malware suffers from a missing authentication vulnerability.

tags | exploit
systems | windows
SHA-256 | 66a256be78a2b1d91b956393409c7f0a32d982b983ecafe35a22a1891897363b
Page 1 of 7
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close