what you don't know can hurt you
Showing 1 - 25 of 45 RSS Feed

Files from Patrick Webster

Real NamePatrick Webster
Email addressprivate
First Active2006-10-02
Last Active2017-08-24
View User Profile

Personal Background

Work at www.osisecurity.com.au and developer for metasploit and occasional OSVDB wrangler.


Trend Micro Hosted Email Security (HES) Interception / Insecure Direct Object Reference
Posted Aug 24, 2017
Authored by Patrick Webster

Trend Micro Hosted Email Security (HES) suffers from email interception and insecure direct object reference vulnerabilities.

tags | exploit, vulnerability
SHA-256 | b05cc034ae6b0b1c59afe01f4ef720d5545f811f1fcc30f3cf6db2bc68cf4f8c
iPlatinum iOneView Cross Site Scripting
Posted Apr 6, 2017
Authored by Patrick Webster

iPlatinum iOneView suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 0748c764b11fe8653d8bdf660e05509be0b81f6592585f84e66a264607caccd8
Moodle 2.4.10 / 2.5.6 / 2.6.3 / 2.7 Account Information Disclosure
Posted Apr 6, 2017
Authored by Patrick Webster

Moodle versions 2.7 and earlier suffer from a vulnerability that discloses the account name for a specified profile ID.

tags | exploit, info disclosure
SHA-256 | 4f976a974fdadab3348c916dd40c13ac770e58b386f43d58b4af5a65ee162dda
Airwatch 6.1.x / 6.4.x LDAP Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Airwatch versions 6.1.x and 6.4.x suffer from an ldap injection vulnerability.

tags | exploit
SHA-256 | de63a8e1e53104e08f13950e374edc66f2fd33fd0b373e7bbf041d5891287eb4
Avaya Radvision SCOPIA Desktop SQL Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Avaya Radvision SCOPIA Desktop versions 7.7.000.042 and 8.2.101.046 suffer from a blind SQL injection vulnerability.

tags | exploit, sql injection
SHA-256 | 9df3a8763b4d5e5041c60ed04a57311756f2452722710236a1bec7035997445b
LanternCMS Cross Site Scripting / SQL Injection
Posted Apr 4, 2017
Authored by Patrick Webster

LanternCMS suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 10d7e8a5a9ae21aa469a8adb55db9076be8af353719bd4c575e7a05d73cca228
SilverStripe CMS 3.1.9 Path Disclosure
Posted Apr 4, 2017
Authored by Patrick Webster

SilverStripe CMS versions 3.1.9 suffers from a path disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | add33c249921191d92637723848b95bc133583d1c0e290741c752d7043e43c6d
SmartJobBoard 5.0.9 Cross Site Scripting / Information Disclosure
Posted Apr 4, 2017
Authored by Patrick Webster

SmartJobBoard version 5.0.9 suffers from cross site scripting and information disclosure vulnerabilities.

tags | exploit, vulnerability, xss, info disclosure
SHA-256 | c79e0d8f6a1f8afcd1cdbe7ed6730c17027d52772fefbc91a7eebe1dc62521f4
Computer Associates (Layer7) API Gateway 7 / 8 / 9 CRLF Response Splitting / Directory Traversal
Posted Apr 4, 2017
Authored by Patrick Webster

Computer Associates API Gateway versions 7, 8, and 9 suffer from CRLF response splitting and directory traversal vulnerabilities.

tags | exploit, vulnerability, file inclusion
SHA-256 | c3dd3bb5978a20a8fe51af9fbf3170c7d9624fcb5b17a87073c4c2abded21d2b
Kaseya VSA 9.02.00.04 Information Disclosure
Posted Apr 4, 2017
Authored by Patrick Webster

Kaseya VSA version 9.02.00.04 suffers from an information disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 5a59d2ffedded5fe54949dd29511e3205fb1e3caac953287dc781deab3742ac4
Trimble / Manhattan Software IWMS 9.x XXE Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Trimble / Manhattan Software IWMS version 9.x suffers from an XML external entity injection vulnerability.

tags | exploit, xxe
SHA-256 | 034d6c464fd8dfb280cc2231b57e61e57db6af0250f94c9a8ef2fd8e71db6e52
Tweek!DM Document Management Bypass / SQL Injection
Posted Apr 4, 2017
Authored by Patrick Webster

Tweek!DM Document Management suffers from bypass and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 990171f149c1422942f3130de220f72cd20ac33b6f5a833745b2d53902b4acdb
Inchoo Facebook Connect Cross Site Scripting
Posted Apr 4, 2017
Authored by Patrick Webster

Inchoo Facebook Connect plugin suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3b57827980094611b40d59abdcc9cf5477a6100b8983ee3cadbc5ac782f744d0
AcoraCMS 7.0.0.6 Browser Redirect / Cross Site Scripting
Posted Apr 4, 2017
Authored by Patrick Webster

AcoraCMS version 7.0.0.6 suffers from arbitrary browser redirect and cross site scripting vulnerabilities.

tags | exploit, arbitrary, vulnerability, xss
SHA-256 | b87426ec9fff88fdce255750542faa9c5b3eef962346cece91f55d16975ad4b2
Kaseya VSA 6.5.0.0 XSS / Brute Force
Posted Apr 4, 2017
Authored by Patrick Webster

Kaseya VSA version 6.5.0.0 suffers from cross site scripting and brute forcing vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 7fe218cd1c415fe7ecf706fc430277ad0a16b68a9d7aa68e327097eb8897004b
ObSecure ObSecure360 Unauthenticated SQL Injection
Posted Dec 23, 2014
Authored by Patrick Webster

ObSecure ObSecure360 suffers from an unauthenticated remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | fa4d57dbca10c2118333bd095376533d52e59a640ac03e1c53419ae9f8c0c50d
Lotus Mail Encryption Server (Protector for Mail) Local File Inclusion
Posted Dec 22, 2014
Authored by Patrick Webster | Site metasploit.com

This Metasploit module exploits a local file inclusion vulnerability in the Lotus Mail Encryption Server (Protector for Mail Encryption) administration setup interface. The index.php file uses an unsafe include() where an unauthenticated remote user may read (traversal) arbitrary file contents. By abusing a second bug within Lotus, we can inject our payload into a known location and call it via the LFI to gain remote code execution. Version 2.1.0.1 Build(88.3.0.1.4323) is known to be vulnerable. You may need to set DATE in the format YYYY-MM-DD to get this working, where the remote host and metasploit instance have UTC timezone differences.

tags | exploit, remote, arbitrary, local, php, code execution, file inclusion
advisories | OSVDB-87556
SHA-256 | 96dbd26ee71f67057f541ea0a3081085a8e98bc7c5079679244febd71f971874
Varnish Cache CLI Interface Remote Code Execution
Posted Dec 20, 2014
Authored by Patrick Webster | Site metasploit.com

This Metasploit module attempts to login to the Varnish Cache (varnishd) CLI instance using a bruteforce list of passwords. This Metasploit module will also attempt to read the /etc/shadow root password hash if a valid password is found. It is possible to execute code as root with a valid password, however this is not yet implemented in this module.

tags | exploit, root
advisories | CVE-1999-0502, CVE-2009-2936, OSVDB-67670
SHA-256 | fe293ec94b3dfa7e3027ffc1c7be75b60a403e4ba9e56d55b6442ac2180a0939
Ultra Electronics SSL VPN 7.2.0.19 / 7.4.0.7 SQL Injection / Directory Creation
Posted Oct 3, 2014
Authored by Patrick Webster

Ultra Electronics SSL VPN versions 7.2.0.19 and 7.4.0.7 suffer from directory creation and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 0420214b4d8e7885ff6112c9bce112f874056677399749e6e050d4409241720c
Checkpoint Firewall VPN1 Information Disclosure
Posted Mar 12, 2012
Authored by Patrick Webster

Checkpoint Firewall VPN1 suffers from a remote information disclosure vulnerability.

tags | advisory, remote, info disclosure
SHA-256 | 23ce565b644ac90f408b650bb9e2fce1833dc96007bb898eba2a5b175e6b9423
Elitecore Cyberoam UTM Cross Site Scripting
Posted Jul 20, 2011
Authored by Patrick Webster

Elitecore Cyberoam UTM suffers from a cross site scripting vulnerability. Builds prior to 10.01.0 Build 0739 are affected.

tags | exploit, xss
SHA-256 | b06e6512b53ea8ea20ff4be6e0b06151a0930083acb280cb4531302feec1fb02
Squiz Matrix 4.0.6 / 4.2.2 Cross Site Scripting
Posted Jun 7, 2011
Authored by Patrick Webster

Squiz Matrix versions 4.0.6 and 4.2.2 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 435a3d8dfec7c3f21c7056390d4582ce63e6f475f3e84918594da65d8d50299b
AWStats Totals 1.14 Remote Command Execution
Posted May 26, 2011
Authored by Patrick Webster | Site metasploit.com

This Metasploit module exploits an arbitrary command execution vulnerability in the AWStats Totals PHP script. AWStats Totals version v1.0 - v1.14 are vulnerable.

tags | exploit, arbitrary, php
advisories | CVE-2008-3922, OSVDB-47807
SHA-256 | 5a5ef1d851e7541e28de7b53546932d0881adc18c9f19c4d8ea20156248a6ea5
Civica Spydus Library Management System (LMS) Cross Site Scripting
Posted May 10, 2011
Authored by Patrick Webster

Civica Spydus Library Management System (LMS) suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ccad3046b9c60fd814e72667d9dc6bbdffd60997d5c1267f4d33d7f8e7ea6b90
LANSA aXes Web Terminal Cross Site Scripting
Posted May 1, 2011
Authored by Patrick Webster

LANSA aXes Web Terminal (TN5250) suffers from a cross site scripting vulnerability.

tags | exploit, web, xss
SHA-256 | a015d5357f35b389714d88ff7ffc8b31be4d05cf80d5372754c4d9f4734d92af
Page 1 of 2
Back12Next

File Archive:

May 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    0 Files
  • 2
    May 2nd
    15 Files
  • 3
    May 3rd
    19 Files
  • 4
    May 4th
    24 Files
  • 5
    May 5th
    15 Files
  • 6
    May 6th
    14 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    13 Files
  • 10
    May 10th
    7 Files
  • 11
    May 11th
    99 Files
  • 12
    May 12th
    45 Files
  • 13
    May 13th
    7 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    16 Files
  • 17
    May 17th
    26 Files
  • 18
    May 18th
    4 Files
  • 19
    May 19th
    17 Files
  • 20
    May 20th
    2 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close