what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 8 of 8 RSS Feed

Files from Riccardo Krauter

Email addressriccardo.krauter at gmail.com
First Active2019-09-03
Last Active2024-09-01
Total.js Prior To 3.2.4 Directory Traversal
Posted Sep 1, 2024
Authored by Fabio Cogno, Riccardo Krauter | Site metasploit.com

This Metasploit module check and exploits a directory traversal vulnerability in Total.js prior to 3.2.4. Here is a list of accepted extensions: flac, jpg, jpeg, png, gif, ico, js, css, txt, xml, woff, woff2, otf, ttf, eot, svg, zip, rar, pdf, docx, xlsx, doc, xls, html, htm, appcache, manifest, map, ogv, ogg, mp4, mp3, webp, webm, swf, package, json, md, m4v, jsx, heif, heic.

tags | exploit
advisories | CVE-2019-8903
SHA-256 | 62c4f347fef628a4909ab5a3ca0be5d96b1c9558b693d37ca09953ff8036bc67
CMS Made Simple 2.2.15 Shell Upload
Posted Mar 21, 2021
Authored by Riccardo Krauter

CMS Made Simple version 2.2.15 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 2cadbab965f878e44ea0acc56a8ffd9d1c8276f1fe9da36588406a2934542549
CMS Made Simple 2.2.15 SQL Injection
Posted Mar 20, 2021
Authored by Riccardo Krauter

CMS Made Simple version 2.2.15 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 3f21f4e492d11451203a608c3eae00dbd7eca2a00545ae32201c11b597edcf87
Total.js CMS 12 Widget JavaScript Code Injection
Posted Oct 21, 2019
Authored by sinn3r, Riccardo Krauter | Site metasploit.com

This Metasploit module exploits a vulnerability in Total.js CMS. The issue is that a user with admin permission can embed a malicious JavaScript payload in a widget, which is evaluated server side, and gain remote code execution.

tags | exploit, remote, javascript, code execution
advisories | CVE-2019-15954
SHA-256 | 994055352fee2d951e405c99aeadd99178b2c65c81e77f2f5498366d48a48c14
Totaljs CMS 12.0 Improper Access Control
Posted Sep 3, 2019
Authored by Riccardo Krauter

Totaljs CMS version 12.0 suffers from a broken access control on an API call.

tags | exploit
SHA-256 | fdf156b531b1d3da98ee95bbd5364b284446474608142fd65919a9598d6d86a7
Totaljs CMS 12.0 Widget Creation Code Injection
Posted Sep 3, 2019
Authored by Riccardo Krauter

Totaljs CMS version 12.0 suffers from an authenticated code injection vulnerability during widget creation.

tags | exploit
SHA-256 | e84a3b40aad34be56be0995eaa9961a7ed8b23cec1171398351a1e261546a2b6
Totaljs CMS 12.0 Insecure Admin Session Cookie
Posted Sep 3, 2019
Authored by Riccardo Krauter

Totaljs CMS version 12.0 mints an insecure cookie that can be used to crack the administrator password.

tags | exploit, insecure cookie handling
SHA-256 | 6df69239605e353638050aa0d99b6229a04afd43b2e3d8b39f3f681e5e2d1305
Totaljs CMS 12.0 Path Traversal
Posted Sep 3, 2019
Authored by Riccardo Krauter

Totaljs CMS version 12.0 suffers from a path traversal vulnerability.

tags | exploit, file inclusion
advisories | CVE-2019-15952
SHA-256 | 9b5f7333d390a6dfbc2864452ec1c372bb2acd344d08dc82ae02bfc49c40aae5
Page 1 of 1
Back1Next

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close