Exploit the possiblities
Showing 1 - 25 of 45 RSS Feed

Files from Patrick Webster

Real NamePatrick Webster
Email addressprivate
First Active2006-10-02
Last Active2017-08-24
View User Profile

Personal Background

Work at www.osisecurity.com.au and developer for metasploit and occasional OSVDB wrangler.


Trend Micro Hosted Email Security (HES) Interception / Insecure Direct Object Reference
Posted Aug 24, 2017
Authored by Patrick Webster

Trend Micro Hosted Email Security (HES) suffers from email interception and insecure direct object reference vulnerabilities.

tags | exploit, vulnerability
MD5 | 59711b501b899ebce98f15aef708ccfd
iPlatinum iOneView Cross Site Scripting
Posted Apr 6, 2017
Authored by Patrick Webster

iPlatinum iOneView suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 3f9fed4ce85ee1fede4977bc23ef4a4a
Moodle 2.4.10 / 2.5.6 / 2.6.3 / 2.7 Account Information Disclosure
Posted Apr 6, 2017
Authored by Patrick Webster

Moodle versions 2.7 and earlier suffer from a vulnerability that discloses the account name for a specified profile ID.

tags | exploit, info disclosure
MD5 | 3e167578263db5e084328661c2ca6f40
Airwatch 6.1.x / 6.4.x LDAP Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Airwatch versions 6.1.x and 6.4.x suffer from an ldap injection vulnerability.

tags | exploit
MD5 | 9d018230a0e76872a86fc0f1fc60d245
Avaya Radvision SCOPIA Desktop SQL Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Avaya Radvision SCOPIA Desktop versions 7.7.000.042 and 8.2.101.046 suffer from a blind SQL injection vulnerability.

tags | exploit, sql injection
MD5 | cb948fff839267811b4cfb5cd76607b0
LanternCMS Cross Site Scripting / SQL Injection
Posted Apr 4, 2017
Authored by Patrick Webster

LanternCMS suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | c6dc19aaa740a4e40266054eac2de5a3
SilverStripe CMS 3.1.9 Path Disclosure
Posted Apr 4, 2017
Authored by Patrick Webster

SilverStripe CMS versions 3.1.9 suffers from a path disclosure vulnerability.

tags | exploit, info disclosure
MD5 | de0e6325711ba6bd4d30f70771525932
SmartJobBoard 5.0.9 Cross Site Scripting / Information Disclosure
Posted Apr 4, 2017
Authored by Patrick Webster

SmartJobBoard version 5.0.9 suffers from cross site scripting and information disclosure vulnerabilities.

tags | exploit, vulnerability, xss, info disclosure
MD5 | 70a0ad7b8292144d4c2b0090c4b03c63
Computer Associates (Layer7) API Gateway 7 / 8 / 9 CRLF Response Splitting / Directory Traversal
Posted Apr 4, 2017
Authored by Patrick Webster

Computer Associates API Gateway versions 7, 8, and 9 suffer from CRLF response splitting and directory traversal vulnerabilities.

tags | exploit, vulnerability, file inclusion
MD5 | aa9a6a201080c8ae019201036b421b1b
Kaseya VSA 9.02.00.04 Information Disclosure
Posted Apr 4, 2017
Authored by Patrick Webster

Kaseya VSA version 9.02.00.04 suffers from an information disclosure vulnerability.

tags | exploit, info disclosure
MD5 | d8342ca721048f9dbe543531be1a409f
Trimble / Manhattan Software IWMS 9.x XXE Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Trimble / Manhattan Software IWMS version 9.x suffers from an XML external entity injection vulnerability.

tags | exploit
MD5 | 79d5a18add30ebddc512e1a4491ee38a
Tweek!DM Document Management Bypass / SQL Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Tweek!DM Document Management suffers from bypass and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
MD5 | 0160f108df220a9e29b0cb1baa6bcd65
Inchoo Facebook Connect Cross Site Scripting
Posted Apr 4, 2017
Authored by Patrick Webster

Inchoo Facebook Connect plugin suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 5a0e026b50724d8c4897217a8c2acb1e
AcoraCMS 7.0.0.6 Browser Redirect / Cross Site Scripting
Posted Apr 4, 2017
Authored by Patrick Webster

AcoraCMS version 7.0.0.6 suffers from arbitrary browser redirect and cross site scripting vulnerabilities.

tags | exploit, arbitrary, vulnerability, xss
MD5 | ebf9294c3ed3902b8146bd20c62ca6bf
Kaseya VSA 6.5.0.0 XSS / Brute Force
Posted Apr 4, 2017
Authored by Patrick Webster

Kaseya VSA version 6.5.0.0 suffers from cross site scripting and brute forcing vulnerabilities.

tags | exploit, vulnerability, xss
MD5 | 422ace8363b61c9858ef75bd8a974044
ObSecure ObSecure360 Unauthenticated SQL Injection
Posted Dec 23, 2014
Authored by Patrick Webster

ObSecure ObSecure360 suffers from an unauthenticated remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | c4efdb15732d4728caa77aa5712c320f
Lotus Mail Encryption Server (Protector for Mail) Local File Inclusion
Posted Dec 22, 2014
Authored by Patrick Webster | Site metasploit.com

This Metasploit module exploits a local file inclusion vulnerability in the Lotus Mail Encryption Server (Protector for Mail Encryption) administration setup interface. The index.php file uses an unsafe include() where an unauthenticated remote user may read (traversal) arbitrary file contents. By abusing a second bug within Lotus, we can inject our payload into a known location and call it via the LFI to gain remote code execution. Version 2.1.0.1 Build(88.3.0.1.4323) is known to be vulnerable. You may need to set DATE in the format YYYY-MM-DD to get this working, where the remote host and metasploit instance have UTC timezone differences.

tags | exploit, remote, arbitrary, local, php, code execution, file inclusion
advisories | OSVDB-87556
MD5 | f20974232a7a23b159fd5584f81f5ae8
Varnish Cache CLI Interface Remote Code Execution
Posted Dec 20, 2014
Authored by Patrick Webster | Site metasploit.com

This Metasploit module attempts to login to the Varnish Cache (varnishd) CLI instance using a bruteforce list of passwords. This Metasploit module will also attempt to read the /etc/shadow root password hash if a valid password is found. It is possible to execute code as root with a valid password, however this is not yet implemented in this module.

tags | exploit, root
advisories | CVE-1999-0502, CVE-2009-2936, OSVDB-67670
MD5 | d65f2e946602f71cbd4d008190d356fe
Ultra Electronics SSL VPN 7.2.0.19 / 7.4.0.7 SQL Injection / Directory Creation
Posted Oct 3, 2014
Authored by Patrick Webster

Ultra Electronics SSL VPN versions 7.2.0.19 and 7.4.0.7 suffer from directory creation and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
MD5 | c14a5043b81312f347548efa8b574674
Checkpoint Firewall VPN1 Information Disclosure
Posted Mar 12, 2012
Authored by Patrick Webster

Checkpoint Firewall VPN1 suffers from a remote information disclosure vulnerability.

tags | advisory, remote, info disclosure
MD5 | 048e312263043ef2c204bb05e575f45c
Elitecore Cyberoam UTM Cross Site Scripting
Posted Jul 20, 2011
Authored by Patrick Webster

Elitecore Cyberoam UTM suffers from a cross site scripting vulnerability. Builds prior to 10.01.0 Build 0739 are affected.

tags | exploit, xss
MD5 | a85da37ecd3d19db557bb94699005da7
Squiz Matrix 4.0.6 / 4.2.2 Cross Site Scripting
Posted Jun 7, 2011
Authored by Patrick Webster

Squiz Matrix versions 4.0.6 and 4.2.2 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 5ec740682485bd9dbf1eb43027161693
AWStats Totals 1.14 Remote Command Execution
Posted May 26, 2011
Authored by Patrick Webster | Site metasploit.com

This Metasploit module exploits an arbitrary command execution vulnerability in the AWStats Totals PHP script. AWStats Totals version v1.0 - v1.14 are vulnerable.

tags | exploit, arbitrary, php
advisories | CVE-2008-3922, OSVDB-47807
MD5 | b51970618acc82762fe370a163a1d655
Civica Spydus Library Management System (LMS) Cross Site Scripting
Posted May 10, 2011
Authored by Patrick Webster

Civica Spydus Library Management System (LMS) suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 58bb515f5c8b5164efbb9250ac60c622
LANSA aXes Web Terminal Cross Site Scripting
Posted May 1, 2011
Authored by Patrick Webster

LANSA aXes Web Terminal (TN5250) suffers from a cross site scripting vulnerability.

tags | exploit, web, xss
MD5 | f805ffdca8a18d42a0487f86b6bf8a96
Page 1 of 2
Back12Next

File Archive:

November 2017

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    22 Files
  • 2
    Nov 2nd
    28 Files
  • 3
    Nov 3rd
    10 Files
  • 4
    Nov 4th
    1 Files
  • 5
    Nov 5th
    5 Files
  • 6
    Nov 6th
    15 Files
  • 7
    Nov 7th
    15 Files
  • 8
    Nov 8th
    13 Files
  • 9
    Nov 9th
    9 Files
  • 10
    Nov 10th
    9 Files
  • 11
    Nov 11th
    3 Files
  • 12
    Nov 12th
    2 Files
  • 13
    Nov 13th
    15 Files
  • 14
    Nov 14th
    17 Files
  • 15
    Nov 15th
    19 Files
  • 16
    Nov 16th
    15 Files
  • 17
    Nov 17th
    19 Files
  • 18
    Nov 18th
    4 Files
  • 19
    Nov 19th
    2 Files
  • 20
    Nov 20th
    9 Files
  • 21
    Nov 21st
    14 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close