what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 21 of 21 RSS Feed

Files Date: 2017-03-01

Veritas NetBackup DoS / Command Execution / Privilege Escalation / Traversal
Posted Mar 1, 2017
Authored by Andrew Griffiths, Google Security Research, Sven Blumenstein, Xiaoran Wang

Veritas NetBackup versions 6.5.6 and 7.6.10 suffer from remote command execution, denial of service, path traversal, and privilege escalation vulnerabilities.

tags | exploit, remote, denial of service, vulnerability, file inclusion
SHA-256 | fbc0e17e197a27b1fd0bae15bb4f69d626cea18ab7a047be5ebf20165a1eb24c
WePresent WiPG-1500 Backdoor Account
Posted Mar 1, 2017
Authored by Quentin Olagne

WePresent WiPG-1500 has a backdoor account installed.

tags | exploit
advisories | CVE-2017-6351
SHA-256 | 17839a48df196431201c62c2532aaa9acf9739ba03634e746b90812100f2fd24
Aruba AirWave 8.2.3 XXE Injection / Cross Site Scripting
Posted Mar 1, 2017
Authored by P. Morimoto | Site sec-consult.com

Aruba AirWave versions 8.2.3 and below suffer from XXE injection and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, xxe
advisories | CVE-2016-8526, CVE-2016-8527
SHA-256 | 26d6fd5588cb2706ccd2898c50798a639ccb5ed66cc64b8e72e5688fa5250278
SysGauge 1.5.18 Buffer Overflow
Posted Mar 1, 2017
Authored by Peter Baris

SysGauge version 1.5.18 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
SHA-256 | f96541cc46b2d9634b51aada91c4f36032cbd40a2421de5ba4ff46d0b41807c9
BlueIris 4.5.1.4 Denial Of Service
Posted Mar 1, 2017
Authored by Peter Baris

BlueIris version 4.5.1.4 suffers from a denial of service vulnerability.

tags | exploit, denial of service
SHA-256 | a2c5115ad6a37fa750e172519882082ffa411085aa72f9b8d5413e397f0148c9
Meme Maker Script 2.1 SQL Injection
Posted Mar 1, 2017
Authored by Ihsan Sencan

Meme Maker Script version 2.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 3b680b1eea85ef4f48ef5800fc8f6755ef642152ecb4e4066e93a5f79c6d8b55
Synchronet BBS 3.16c For Windows Denial Of Service
Posted Mar 1, 2017
Authored by Peter Baris

Synchronet BBS versions 3.16c for Windows suffers from denial of service vulnerabilities.

tags | exploit, denial of service, vulnerability
systems | windows
advisories | CVE-2017-6371
SHA-256 | a681bf492f0e36b93a7fc183338830d0a1f80483c5bd6e997784651d80b2c7d0
Rage Faces Script 1.3 SQL Injection
Posted Mar 1, 2017
Authored by Ihsan Sencan

Rage Faces Script version 1.3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | a939cfe1fb5829636cdac4246585ffa4d9e023d3c7cf83515fb474b246beddb6
Linux/x86-64 Reverse Shell Shellcode
Posted Mar 1, 2017
Authored by Manuel Mancera

84 bytes small Linux/x86-64 reverse shell shellcode.

tags | shell, x86, shellcode
systems | linux
SHA-256 | f168c1f1f36a8117fccc0ba9a8c292fb68070285c33d750866af2ec3353d836e
D-Link DSL-2730U Wireless N 150 Cross Site Request Forgery
Posted Mar 1, 2017
Authored by B GOVIND

D-Link DSL-2730U Wireless N 150 suffers from cross site request forgery vulnerabilities.

tags | exploit, vulnerability, csrf
advisories | CVE-2017-6411
SHA-256 | 8a8d39643221306911e1ebc9e7fe18a969319fc139f6155ad1683590b57c4de0
WordPress Trust Form 2.0 Cross Site Scripting
Posted Mar 1, 2017
Authored by Yorick Koster, Securify B.V.

WordPress Trust Form plugin version 2.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f0520b62eba5142812d52e24b0842400be91238307a22751b2fc0270207501f7
WordPress Analytics Stats Counter Statistics 1.2.2.5 PHP Object Injection
Posted Mar 1, 2017
Authored by Yorick Koster, Securify B.V.

WordPress Analytics Stats Counter Statistics plugin version 1.2.2.5 suffers from a PHP object injection vulnerability.

tags | advisory, php
SHA-256 | d1935f94c13d237a769e00666940587d42964a0f386dbc6ac59063ea3b38e413
osTicket 1.9.12 Cross Site Scripting
Posted Mar 1, 2017
Authored by Han Sahin

osTicket version 1.9.12 suffers from multiple persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | c97da578520b0fab8d0625cbd24015f598369f9b2be34ed0c37ea35a53f87da2
Windows x86 Reverse TCP Staged Alphanumeric Shellcode
Posted Mar 1, 2017
Authored by Snir Levi

322 bytes small Windows x86 reverse TCP staged alphanumeric shellcode.

tags | x86, tcp, shellcode
systems | windows
SHA-256 | e392c28549e212edefc14d36ba95313226d72ff59c0520ebcbd9c1d0ea0ee1cd
WordPress WP-Filebase Download Manager 3.4.4 Cross Site Scripting
Posted Mar 1, 2017
Authored by Yorick Koster, Securify B.V.

WordPress WP-Filebase Download Manager plugin version 3.4.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 979fbbeecfa00a214223f001ac5c8d271726113e0cf0f2b7d1d6a1a6d7cb5942
WordPress Admin Custom Login 2.4.5.2 Cross Site Scripting
Posted Mar 1, 2017
Authored by Securify B.V., Burak Kelebek

WordPress Admin Custom Login plugin version 2.4.5.2 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 6d78f22f7c67f695ae49fc60ee47fad5693fd927af00a1ecb56df1fdaf5bd89c
JexBoss: Jboss verify and EXploitation Tool
Posted Mar 1, 2017
Authored by Joao F M Figueiredo

JexBoss is an exploitation tool that demonstrates deserialization remote code execution attacks against multiple applications and platforms.

tags | exploit, remote, code execution
SHA-256 | aeb7832bfac3aaa324b3d6950c3ff7b7b82470cbcb90aeff584aa5ef011c82f5
WordPress WP-SpamFree Anti-Spam 2.1.1.4 Cross Site Scripting
Posted Mar 1, 2017
Authored by Securify B.V., Radjnies Bhansingh

WordPress WP-SpamFree Anti-Spam plugin version 2.1.1.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | db5dbfcbe4a5e667c55abb55d4576550faf4d3a1fe318516f8a382e265bfffd1
SchoolDir SQL Injection
Posted Mar 1, 2017
Authored by Ihsan Sencan

SchoolDir suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 376eb17e31241b67a7372e39547a62fd9f325c32ec08ad696bc079f6ca7856ea
SQLMAP - Automatic SQL Injection Tool 1.1.3-4
Posted Mar 1, 2017
Authored by Bernardo Damele | Site sqlmap.org

sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.

Changes: Major improvements to program stabilization based on user reports. Added new tampering scripts avoiding popular WAF/IPS/IDS mechanisms. Fixed major bug with DNS leaking in Tor mode. Various other support added.
tags | tool, web, overflow, arbitrary, vulnerability, sql injection
systems | unix
SHA-256 | 41e3f47071c41caae1800eeddd98eb6edb87d322184f5e7aab87d4697a2b885f
X.org Privilege Escalation / Use-After-Free / Weak Entropy
Posted Mar 1, 2017
Authored by Eric Sesterhenn

X.org suffers from privilege escalation, weak entropy, and use-after-free vulnerabilities.

tags | exploit, vulnerability
advisories | CVE-2017-2624, CVE-2017-2625, CVE-2017-2626
SHA-256 | f72f05abe9036269c3ae97121d5341b234d6db2cbe445c9d8643a82f22648e4d
Page 1 of 1
Back1Next

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close