exploit the possibilities
Showing 1 - 25 of 453 RSS Feed

Files Date: 2020-12-01 to 2020-12-31

EgavilanMedia My To Do List 1.0 Cross Site Scripting
Posted Dec 30, 2020
Authored by Dwiki Kusuma

EgavilanMedia My To Do List version 1.0 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
MD5 | f233fa18dbd5fcbeaf2b183be2637b7e
OATH Toolkit 2.6.5
Posted Dec 29, 2020
Site nongnu.org

OATH Toolkit attempts to collect several tools that are useful when deploying technologies related to OATH, such as HOTP one-time passwords. It is a fork of the earlier HOTP Toolkit.

Changes: Various improvements.
tags | tool
systems | unix
MD5 | 04b9dc96de85204b9fc671e492fce443
HPE Edgeline Infrastructure Manager Improper Authorization
Posted Dec 29, 2020
Authored by Jeremy Brown

HPE Edgeline Infrastructure Manager suffers from multiple broken authorization flows that allow for administrative function access without authenticating and can allow for arbitrary password changes.

tags | exploit, arbitrary
MD5 | 75012bca2029a5ddfe8ad8255b3f5f1b
Cassandra Web 0.5.0 Remote File Read
Posted Dec 29, 2020
Authored by Jeremy Brown

Cassandra Web is vulnerable to directory traversal due to the disabled Rack::Protection module. Apache Cassandra credentials are passed via the CLI in order for the server to auth to it and provide the web access, so they are also one thing that can be captured via the arbitrary file read. Version 0.5.0 is affected.

tags | exploit, web, arbitrary
MD5 | 5d45ddf35f9f55300493bfefe8020924
SEOPanel 4.6.0 Cross Site Scripting
Posted Dec 28, 2020
Authored by Daniel Bishtawi | Site netsparker.com

SEOPanel version 4.6.0 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
MD5 | 1bc25ab0ee208b3cca430a4059f1b493
CHMSC Elearning System 1.0 SQL Injection
Posted Dec 27, 2020
Authored by Ferhat Cil

CHMSC Elearning System version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 77f57674def23ab3a7057704c263a411
URVE Software Build 24.03.2020 Information Disclosure
Posted Dec 27, 2020
Authored by Erik Steltzner | Site sec-consult.com

URVE Software build version 24.03.2020 suffers from an information disclosure vulnerability that leaks passwords.

tags | exploit, info disclosure
advisories | CVE-2020-29550
MD5 | 67a93118486c77b8f926ea8fde0d4842
URVE Software Build 24.03.2020 Missing Authorization
Posted Dec 26, 2020
Authored by Erik Steltzner | Site sec-consult.com

URVE Software build version 24.03.2020 suffers from a missing authorization vulnerability.

tags | exploit
advisories | CVE-2020-29551
MD5 | 21a202af48e3b2d3bba664981efd514b
Philips Hue Denial Of Service
Posted Dec 26, 2020
Authored by Ilia Shnaidman

Philips Hue hubs suffer from a denial of service vulnerability via simple SYN floods.

tags | exploit, denial of service
advisories | CVE-2018-7580
MD5 | 3fd9075a03a9baac3c178dfadfc51fde
URVE Software Build 24.03.2020 Authentication Bypass / Remote Code Execution
Posted Dec 25, 2020
Authored by Erik Steltzner | Site sec-consult.com

URVE Software build version 24.03.2020 suffers from an authentication bypass that allows for remote code execution.

tags | exploit, remote, code execution
advisories | CVE-2020-29552
MD5 | 2558a7df11b7e0c0f83b775d7059d021
CarolinaCon 16 Call For Papers
Posted Dec 25, 2020
Site carolinacon.org

The 16th CarolinaCon was postponed in 2020 due to the pandemic but the conference will be hosted online in 2021. A new CFP has been announced.

tags | paper, conference
MD5 | 2e1ac4156f59b933bd88b2086ce0d990
Apache Struts 2 Forced Multi OGNL Evaluation
Posted Dec 24, 2020
Authored by Matthias Kaiser, Spencer McIntyre, Alvaro Munoz, ka1n4t | Site metasploit.com

The Apache Struts framework, when forced, performs double evaluation of attribute values assigned to certain tags attributes such as id. It is therefore possible to pass in a value to Struts that will be evaluated again when a tag's attributes are rendered. With a carefully crafted request, this can lead to remote code execution. This vulnerability is application dependant. A server side template must make an affected use of request data to render an HTML tag attribute.

tags | exploit, remote, code execution
advisories | CVE-2019-0230, CVE-2020-17530
MD5 | a00ae15a323f6cf0ba8c86991a9f2707
Lynis Auditing Tool 3.0.2
Posted Dec 24, 2020
Authored by Michael Boelen | Site cisofy.com

Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.

Changes: Added OS detection of Flatcar, IPFire, Mageia, NixOS, ROSA Linux, SLES (extended), Void Linux, Zorin OS. Support for Solaris svcs added. Many other additions and changes.
tags | tool, scanner
systems | unix
MD5 | 1b01474e4efaa68a7ad929a93a98fd35
Faraday 3.14.0
Posted Dec 24, 2020
Authored by Francisco Amato | Site github.com

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

Changes: Added RESTless filter to multiples views, improving search. Added import vulnerability templates command to faraday-manage. Added a create_date field to comments. Various other additions and fixes.
tags | tool, rootkit
systems | unix
MD5 | 3061690f2afe841ba29e533a26372b79
Arteco Web Client DVR/NVR Session Hijacking
Posted Dec 24, 2020
Authored by LiquidWorm | Site zeroscience.mk

The session identifier used by Arteco Web Client DVR/NVR is of an insufficient length and can be brute forced, allowing a remote attacker to obtain a valid session, bypass authentication, and disclose the live camera stream.

tags | exploit, remote, web
MD5 | cb6db35d7f26517c312bbf4e1a19976e
Gentoo Linux Security Advisory 202012-24
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-24 - Multiple vulnerabilities have been found in Samba, the worst of which could result in a Denial of Service condition. Versions less than 4.12.9 are affected.

tags | advisory, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2020-14318, CVE-2020-14323, CVE-2020-14383, CVE-2020-1472
MD5 | 5bb991544b7b094ea08997f5d5fa0908
Gentoo Linux Security Advisory 202012-23
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-23 - A vulnerability has been discovered in Apache Tomcat that allows for the disclosure of sensitive information. Versions less than 8.5.60:8.5 are affected.

tags | advisory
systems | linux, gentoo
advisories | CVE-2020-17527
MD5 | 4b45bfe2024aae3d31806bf1ae19f590
Gentoo Linux Security Advisory 202012-22
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-22 - A buffer overflow in HAProxy might allow an attacker to execute arbitrary code. Versions less than 2.1.4 are affected.

tags | advisory, overflow, arbitrary
systems | linux, gentoo
advisories | CVE-2020-11100
MD5 | cc63f4b1c5abcfdc237602d305cf4cd2
Gentoo Linux Security Advisory 202012-21
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-21 - A vulnerability in NSS might allow remote attackers to cause a Denial of Service condition. Versions less than 3.58 are affected.

tags | advisory, remote, denial of service
systems | linux, gentoo
advisories | CVE-2020-25648
MD5 | 099b9521757862123b4938671037ce9d
Gentoo Linux Security Advisory 202012-20
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-20 - Multiple vulnerabilities have been found in Mozilla Firefox and Mozilla Thunderbird, the worst of which could result in the arbitrary execution of code. Versions less than 84.0 are affected.

tags | advisory, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2020-16042, CVE-2020-26971, CVE-2020-26973, CVE-2020-26974, CVE-2020-26978, CVE-2020-35111, CVE-2020-35113
MD5 | e3745dbe6ac37ed3f38ad62cc7dea0ca
Gentoo Linux Security Advisory 202012-19
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-19 - A vulnerability in PowerDNS Recursor could lead to a Denial of Service condition. Versions less than 4.3.5 are affected.

tags | advisory, denial of service
systems | linux, gentoo
advisories | CVE-2020-25829
MD5 | bca7f54ceba881be5a65594892a18f34
WordPress Adning Advertising 1.5.5 Shell Upload
Posted Dec 24, 2020
Authored by spacehen

Adning Advertising plugin version 1.5.5 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
MD5 | 4533cad4ba378e377d042ba106f71deb
Gentoo Linux Security Advisory 202012-18
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-18 - An information disclosure vulnerability in PowerDNS allow remote attackers to obtain sensitive information. Versions less than 4.3.1 are affected.

tags | advisory, remote, info disclosure
systems | linux, gentoo
advisories | CVE-2020-17482
MD5 | c3f0b4988dbd837f82232d976e921338
Gentoo Linux Security Advisory 202012-17
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-17 - A local Denial of Service vulnerability was discovered in D-Bus. Versions less than 1.12.20 are affected.

tags | advisory, denial of service, local
systems | linux, gentoo
MD5 | 982320c1adcfa69f4b83182f45d384ad
Gentoo Linux Security Advisory 202012-16
Posted Dec 24, 2020
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 202012-16 - Multiple vulnerabilities have been found in PHP, the worst of which could result in a Denial of Service condition. Versions less than 8.0.0 are affected.

tags | advisory, denial of service, php, vulnerability
systems | linux, gentoo
advisories | CVE-2020-7069, CVE-2020-7070
MD5 | 96e08b0d750daa800cc55885a3ab17ec
Page 1 of 19
Back12345Next

File Archive:

April 2021

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    17 Files
  • 2
    Apr 2nd
    2 Files
  • 3
    Apr 3rd
    2 Files
  • 4
    Apr 4th
    0 Files
  • 5
    Apr 5th
    15 Files
  • 6
    Apr 6th
    15 Files
  • 7
    Apr 7th
    20 Files
  • 8
    Apr 8th
    16 Files
  • 9
    Apr 9th
    5 Files
  • 10
    Apr 10th
    0 Files
  • 11
    Apr 11th
    0 Files
  • 12
    Apr 12th
    4 Files
  • 13
    Apr 13th
    15 Files
  • 14
    Apr 14th
    27 Files
  • 15
    Apr 15th
    19 Files
  • 16
    Apr 16th
    7 Files
  • 17
    Apr 17th
    1 Files
  • 18
    Apr 18th
    1 Files
  • 19
    Apr 19th
    19 Files
  • 20
    Apr 20th
    18 Files
  • 21
    Apr 21st
    30 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close