what you don't know can hurt you
Showing 1 - 25 of 392 RSS Feed

Files Date: 2019-03-01 to 2019-03-31

Cisco RV320 / RV325 Unauthenticated Remote Code Execution
Posted Mar 30, 2019
Authored by Philip Huppert, RedTeam Pentesting GmbH, Benjamin Grap | Site metasploit.com

This Metasploit module combines an information disclosure (CVE-2019-1653) and a command injection vulnerability (CVE-2019-1652) together to gain unauthenticated remote code execution on Cisco RV320 and RV325 small business routers. Can be exploited via the WAN interface of the router. Either via HTTPS on port 443 or HTTP on port 8007 on some older firmware versions.

tags | exploit, remote, web, code execution, info disclosure
systems | cisco
advisories | CVE-2019-1652, CVE-2019-1653
MD5 | 7c621eb89c6b32e552d814e012fad4b9
CentOS Web Panel 0.9.8.789 Cross Site Scripting
Posted Mar 29, 2019
Authored by DKM

CentOS Web Panel version 0.9.8.78 suffers from a persistent cross site scripting vulnerability.

tags | exploit, web, xss
systems | linux, centos
advisories | CVE-2019-10261
MD5 | f8dd24fc9d2d944a62b8241eb836aa56
Pydio 8 Command Execution / Cross Site Scripting
Posted Mar 29, 2019
Authored by Leandro Cuozzo, Ramiro Molina | Site secureauth.com

Pydio 8 suffers from cross site scripting, command injection, and various other vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2019-10045, CVE-2019-10046, CVE-2019-10047, CVE-2019-10048, CVE-2019-10049
MD5 | 4bbf5f61cb3b1078960683a0b5c13dbc
Debian Security Advisory 4418-1
Posted Mar 29, 2019
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4418-1 - A vulnerability was discovered in the Dovecot email server. When reading FTS or POP3-UIDL headers from the Dovecot index, the input buffer size is not bounds-checked. An attacker with the ability to modify dovecot indexes, can take advantage of this flaw for privilege escalation or the execution of arbitrary code with the permissions of the dovecot user. Only installations using the FTS or pop3 migration plugins are affected.

tags | advisory, arbitrary
systems | linux, debian
advisories | CVE-2019-7524
MD5 | 4e1a2f468792a0aeca021bb8b40fffcb
VMware Security Advisory 2019-0005
Posted Mar 29, 2019
Authored by VMware | Site vmware.com

VMware Security Advisory 2019-0005 - VMware ESXi, Workstation and Fusion updates address multiple security issues.

tags | advisory
advisories | CVE-2019-5514, CVE-2019-5515, CVE-2019-5518, CVE-2019-5519, CVE-2019-5524
MD5 | 8d7829a21cc009037128f8bf2d178e1b
VMware Security Advisory 2019-0004
Posted Mar 29, 2019
Authored by VMware | Site vmware.com

VMware Security Advisory 2019-0004 - VMware vCloud Director for Service Providers update resolves a Remote Session Hijack vulnerability.

tags | advisory, remote
advisories | CVE-2019-5523
MD5 | 8f3ca8321cfd810fd65b4198893d7205
Ubuntu Security Notice USN-3927-1
Posted Mar 29, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3927-1 - It was discovered that Thunderbird allowed PAC files to specify that requests to localhost are sent through the proxy to another server. If proxy auto-detection is enabled, an attacker could potentially exploit this to conduct attacks on local services and tools. Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, or execute arbitrary code. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary, local
systems | linux, ubuntu
advisories | CVE-2018-18506, CVE-2019-9792, CVE-2019-9793, CVE-2019-9795, CVE-2019-9810
MD5 | 0d66fa4f21353894c143dec150943113
Ubuntu Security Notice USN-3918-3
Posted Mar 29, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3918-3 - USN-3918-1 fixed vulnerabilities in Firefox. The update caused web compatibility issues with some websites. This update fixes the problem. Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, denial of service via successive FTP authorization prompts or modal alerts, trick the user with confusing permission request prompts, obtain sensitive information, conduct social engineering attacks, or execute arbitrary code. A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. If a user were tricked in to opening a specially crafted website with Spectre mitigations disabled, an attacker could potentially exploit this to cause a denial of service, or execute arbitrary code. It was discovered that Upgrade-Insecure-Requests was incorrectly enforced for same-origin navigation. An attacker could potentially exploit this to conduct man-in-the-middle attacks. Various other issues were also addressed.

tags | advisory, web, denial of service, arbitrary, vulnerability
systems | linux, ubuntu
advisories | CVE-2019-9791, CVE-2019-9793, CVE-2019-9799, CVE-2019-9803, CVE-2019-9808
MD5 | 79d2df9d3251aec55839d0a5fa67270f
Ubuntu Security Notice USN-3925-1
Posted Mar 29, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3925-1 - It was discovered that an out-of-bounds write vulnerability existed in the XMP Image handling functionality of the FreeImage library. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could overwrite arbitrary memory, resulting in code execution.

tags | advisory, remote, arbitrary, code execution
systems | linux, ubuntu
advisories | CVE-2016-5684
MD5 | 857c2829c855cabfe01facfea0086175
Magento 2.3.0 SQL Injection
Posted Mar 29, 2019
Authored by Charles FOL

Magento versions 2.2.0 through 2.3.0 unauthenticated remote SQL injection exploit.

tags | exploit, remote, sql injection
MD5 | fd9d593a8b6ef880b62253bdde56c246
SpiderMonkey IonMonkey Type Confusion
Posted Mar 29, 2019
Authored by saelo, Google Security Research

A bug in IonMonkey leaves type inference information inconsistent, which in turn allows the compilation of JITed functions that cause type confusions between arbitrary objects.

tags | exploit, arbitrary
advisories | CVE-2019-9813
MD5 | cdcb535655303de5282b8e9ce3804be5
Job Portal 3.1 SQL Injection
Posted Mar 29, 2019
Authored by Mehmet Emiroglu

Job Portal version 3.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | ea89e98207f68fe80916e9852460d6e1
BigTree CMS 4.3.4 SQL Injection
Posted Mar 29, 2019
Authored by Mehmet Emiroglu

BigTree CMS version 4.3.4 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
MD5 | 6a38bc0643f90db9afb86befcc862891
Jettweb PHP Hazir Rent A Car Sitesi Scripti 2 SQL Injection
Posted Mar 29, 2019
Authored by Ahmet Umit Bayram

Jettweb PHP Hazir Rent A Car Sitesi Scripti version 2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 18f62a5e5ad9bc383565459c869d1942
Thomson Reuters Concourse And Firm Central Local File Inclusion / Directory Traversal
Posted Mar 29, 2019
Authored by 0v3rride

Thomson Reuters Concourse and Firm Central versions prior to 2.13.0097 suffer from directory traversal and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, file inclusion
advisories | CVE-2019-8385
MD5 | 2f1c67379d50d0c5a6e338f892cd9916
WordPress Anti-Malware Security And Brute-Force Firewall 4.18.63 Local File Inclusion
Posted Mar 29, 2019
Authored by Ali S. Ahmad

WordPress Anti-Malware Security and Brute-Force Firewall plugin version 4.18.63 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
MD5 | c3c8b8f52e424c3c1590ab946e0a5361
Base64 Decoder 1.1.2 Buffer Overflow
Posted Mar 29, 2019
Authored by Paolo Perego

Base64 Decoder version 1.1.2 local buffer overflow exploit with SEH egghunter.

tags | exploit, overflow, local
MD5 | a69e29293ab28fa6557a6b8fbfc700e3
WordPress Loco Translate 2.2.1 Local File Inclusion
Posted Mar 29, 2019
Authored by Ali S. Ahmad

WordPress Loco Translate plugin version 2.2.1 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
MD5 | c78144a2b2993de8c8224ea551584eb6
Microsoft Visio 2016 16.0.4738.1000 Denial Of Service
Posted Mar 29, 2019
Authored by Cesar Adrian Coronado Llanos

Microsoft Visio 2016 version 16.0.4738.1000 suffers from a denial of service vulnerability.

tags | exploit, denial of service
MD5 | 8d7282b2e6f1370e71dc0af9fb88fc7a
Red Hat Security Advisory 2019-0679-01
Posted Mar 28, 2019
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2019-0679-01 - The libssh2 packages provide a library that implements the SSH2 protocol. Issues addressed include an out of bounds write vulnerability.

tags | advisory, protocol
systems | linux, redhat
advisories | CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3863
MD5 | a11fb2a1695f5e4bec9e5f71c0bc7ab8
Ubuntu Security Notice USN-3924-1
Posted Mar 28, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3924-1 - It was discovered that mod_auth_mellon incorrectly handled certain requests. An attacker could possibly use this issue to redirect a user to a malicious URL. It was discovered that mod_auth_mellon incorrectly handled certain requests. An attacker could possibly use this issue to access sensitive information.

tags | advisory
systems | linux, ubuntu
advisories | CVE-2019-3877, CVE-2019-3878
MD5 | d398943a9939c7638ab540f4147bab7c
Red Hat Security Advisory 2019-0681-01
Posted Mar 28, 2019
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2019-0681-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 60.6.1. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2018-18506, CVE-2019-9788, CVE-2019-9790, CVE-2019-9791, CVE-2019-9792, CVE-2019-9793, CVE-2019-9795, CVE-2019-9796, CVE-2019-9810, CVE-2019-9813
MD5 | 01ac391f7e90be5fbb1920c893aadf29
Red Hat Security Advisory 2019-0680-01
Posted Mar 28, 2019
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2019-0680-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 60.6.1. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2018-18506, CVE-2019-9788, CVE-2019-9790, CVE-2019-9791, CVE-2019-9792, CVE-2019-9793, CVE-2019-9795, CVE-2019-9796, CVE-2019-9810, CVE-2019-9813
MD5 | 1f9333cb1d74207d12f7fc3b22528d84
Slackware Security Advisory - gnutls Updates
Posted Mar 28, 2019
Authored by Slackware Security Team | Site slackware.com

Slackware Security Advisory - New gnutls packages are available for Slackware 14.2 and -current to fix security issues.

tags | advisory
systems | linux, slackware
MD5 | 8ad7925662640a4f9448740a7ff6dff3
Apple Security Advisory 2019-3-27-1
Posted Mar 28, 2019
Authored by Apple | Site apple.com

Apple Security Advisory 2019-3-27-1 - watchOS 5.2 is now available and addresses buffer overflow and code execution vulnerabilities.

tags | advisory, overflow, vulnerability, code execution
systems | apple
advisories | CVE-2019-6207, CVE-2019-6237, CVE-2019-7286, CVE-2019-7292, CVE-2019-7293, CVE-2019-8502, CVE-2019-8506, CVE-2019-8510, CVE-2019-8511, CVE-2019-8514, CVE-2019-8516, CVE-2019-8517, CVE-2019-8518, CVE-2019-8527, CVE-2019-8536, CVE-2019-8540, CVE-2019-8541, CVE-2019-8542, CVE-2019-8544, CVE-2019-8545, CVE-2019-8546, CVE-2019-8548, CVE-2019-8549, CVE-2019-8552, CVE-2019-8553, CVE-2019-8558, CVE-2019-8559, CVE-2019-8563
MD5 | 20bb10399acb33ecc3f407390b3e365d
Page 1 of 16
Back12345Next

File Archive:

June 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    1 Files
  • 2
    Jun 2nd
    2 Files
  • 3
    Jun 3rd
    19 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    15 Files
  • 6
    Jun 6th
    12 Files
  • 7
    Jun 7th
    11 Files
  • 8
    Jun 8th
    1 Files
  • 9
    Jun 9th
    1 Files
  • 10
    Jun 10th
    15 Files
  • 11
    Jun 11th
    15 Files
  • 12
    Jun 12th
    15 Files
  • 13
    Jun 13th
    8 Files
  • 14
    Jun 14th
    16 Files
  • 15
    Jun 15th
    2 Files
  • 16
    Jun 16th
    1 Files
  • 17
    Jun 17th
    18 Files
  • 18
    Jun 18th
    15 Files
  • 19
    Jun 19th
    22 Files
  • 20
    Jun 20th
    14 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close