what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 30 RSS Feed

Files Date: 2021-04-21

Ubuntu Security Notice USN-4923-1
Posted Apr 21, 2021
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 4923-1 - Laszlo Ersek discovered that EDK II incorrectly handled recursion. A remote attacker could possibly use this issue to cause EDK II to consume resources, leading to a denial of service. Satoshi Tanda discovered that EDK II incorrectly handled decompressing certain images. A remote attacker could use this issue to cause EDK II to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2021-28210, CVE-2021-28211
SHA-256 | c6a40eaa9804bcbd688af5e22e4aacb4108392cf23d7cf4f045959af8339a0de
GravCMS 1.10.7 Remote Command Execution
Posted Apr 21, 2021
Authored by Mehmet Ince | Site metasploit.com

This Metasploit module exploits an arbitrary configuration write/update vulnerability to achieve remote code execution. Unauthenticated users can execute a terminal command under the context of the web server user. Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. Particular method execution will result in arbitrary YAML file creation or content change of existing YAML files on the system. Successfully exploitation of that vulnerability results in configuration changes, such as general site information change, custom scheduler job definition, etc. Due to the nature of the vulnerability, an adversary can change some part of the webpage, or hijack an administrator account, or execute operating system command under the context of the web-server user.

tags | exploit, remote, web, arbitrary, code execution
advisories | CVE-2021-21425
SHA-256 | abded99044d29ee61fd87425114e92d627cb24bfd4a08cbdc45f77650c84534d
Nagios XI 5.7.3 Remote Code Execution
Posted Apr 21, 2021
Authored by Chris Lyne, Erik Wynter | Site metasploit.com

This Metasploit module exploits an OS command injection vulnerability in includes/components/nxti/index.php that enables an authenticated user with admin privileges to achieve remote code execution as the apache user. Valid credentials for a Nagios XI admin user are required. This module has been successfully tested against Nagios XI 5.7.3 running on CentOS 7.

tags | exploit, remote, php, code execution
systems | linux, osx, centos
advisories | CVE-2020-5792
SHA-256 | 02c732ecdeb46edeb55c3d07feeea7f934380ef9d317001de2070079b9dae17d
Red Hat Security Advisory 2021-1297-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1297-01 - The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | d2fc9583f02831592db884875277fcf7256755db2717f96597bcc661d0855b25
Cockpit CMS 0.11.1 NoSQL Injection / Remote Command Execution
Posted Apr 21, 2021
Authored by h00die, Nikita Petrov | Site metasploit.com

This Metasploit module exploits two NoSQL injection vulnerabilities to retrieve the user list and password reset tokens from the system. Next, the USER is targeted to reset their password. Then, a command injection vulnerability is used to execute the payload. While it is possible to upload a payload and execute it, the command injection provides a no disk write method which is more stealthy. Cockpit CMS versions 0.10.0 through 0.11.1, inclusive, contain all the necessary vulnerabilities for exploitation.

tags | exploit, vulnerability, sql injection
advisories | CVE-2020-35846, CVE-2020-35847
SHA-256 | 4d68ac3e666ed9ff71dca71ddb5b25a40d4998c467a0dc4dc723c054ae9043cc
Adtran Personal Phone Manager 10.8.1 DNS Exfiltration
Posted Apr 21, 2021
Authored by 3ndG4me

Adtran Personal Phone Manager version 10.8.1 suffers from a DNS exfiltration vulnerability.

tags | exploit
advisories | CVE-2021-25681
SHA-256 | 3dd1867ec938ca429dc56dd3a114be49598fc02680ddbb249fb52cadbbb7641d
Ubuntu Security Notice USN-4922-1
Posted Apr 21, 2021
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 4922-1 - Juho Nurminen discovered that the REXML gem bundled with Ruby incorrectly parsed and serialized XML documents. A remote attacker could possibly use this issue to perform an XML round-trip attack.

tags | advisory, remote, ruby
systems | linux, ubuntu
advisories | CVE-2021-28965
SHA-256 | cf2ecedb6dc196e4af175809b78647a6357efa199acf1dec4b27a28339ad47d1
Red Hat Security Advisory 2021-1298-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1298-01 - The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | 111d7f79cadeeb4e25d52f549c9ef3074496b150b3412a9de6f194c8acffe8f6
Hasura GraphQL 1.3.3 Denial Of Service
Posted Apr 21, 2021
Authored by Dolev Farhi

Hasura GraphQL version 1.3.3 suffers from a denial of service vulnerability.

tags | exploit, denial of service
SHA-256 | 58ed2fb4a19652d286e476e457bd2a816cbd60dacbcd1f29fc6657648aa3128e
Red Hat Security Advisory 2021-1307-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1307-01 - The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | 569022b9b518cc207f856cca35a8373bf368219400d3d6a5a480c359d10bb7b5
OpenEMR 5.0.2.1 Remote Code Execution
Posted Apr 21, 2021
Authored by Hato0, BvThTrd

OpenEMR version 5.0.2.1 remote code execution exploit that drops in a reverse shell.

tags | exploit, remote, shell, code execution
SHA-256 | 19c8469e1f4adb849ff6cc14a09cddd215b6ce8699d9be7ed6adaccfcbba09c2
Red Hat Security Advisory 2021-1306-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1306-01 - The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | c499857d7375f4cf9a1e614722d6d0ef89951cbd839a21fc352c880bdbc4ab87
Tenda D151 / D301 Configuration Download
Posted Apr 21, 2021
Authored by BenChaliah

Tenda versions D151 and D301 configuration downloading exploit.

tags | exploit, info disclosure
SHA-256 | fc37a22e1c47e9ca6660a0c683b311797731fe9a99e2150fcd40d501d3ac38dd
Red Hat Security Advisory 2021-1150-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1150-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Issues addressed include a denial of service vulnerability.

tags | advisory, denial of service
systems | linux, redhat
advisories | CVE-2021-20291
SHA-256 | cb0b05054e01dacfc97259c7111ab5d6358375e32e414ffad4b6c7394ff1feef
Red Hat Security Advisory 2021-1299-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1299-01 - The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | 30a779eacb92e26ef4e4b02eb9a7120bca6ab83b2db2b7f31f91f77a392d1f60
Adtran Personal Phone Manager 10.8.1 Cross Site Scripting
Posted Apr 21, 2021
Authored by 3ndG4me

Adtran Personal Phone Manager version 10.8.1 suffers from multiple reflective cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2021-25680
SHA-256 | 91eb377154488ec7c016952ffe3b4ebf2791bd6838a98d08693e4ebf4db983ba
Adtran Personal Phone Manager 10.8.1 Persistent Cross Site Scripting
Posted Apr 21, 2021
Authored by 3ndG4me

Adtran Personal Phone Manager version 10.8.1 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2021-25679
SHA-256 | 1a74f8201ae6c8c3641611292636c86df375abcf5cbd509ea906e6109f10291e
Hasura GraphQL 1.3.3 Server-Side Request Forgery
Posted Apr 21, 2021
Authored by Dolev Farhi

Hasura GraphQL version 1.3.3 suffers from a server-side request forgery vulnerability.

tags | exploit
SHA-256 | 05cf663a02092c1f333b7942d756aca4b12b9239512514eee13081444f037125
Red Hat Security Advisory 2021-1305-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1305-01 - The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | 99ad2593f5159777a59279ce8f64cb038e76214bfaefce17b4c14cd7a403e4b6
Hasura GraphQL 1.3.3 Arbitrary File Read
Posted Apr 21, 2021
Authored by Dolev Farhi

Hasura GraphQL version 1.3.3 suffers from an arbitrary file read vulnerability.

tags | exploit, arbitrary
SHA-256 | 8378720189b6d8e38a67594bb98e3dcd9bbc8ec7b0b661c2f36049eff3a5c2ba
rconfig 3.9.6 Shell Upload
Posted Apr 21, 2021
Authored by Vishwaraj Bhattrai

rconfig versions 3.9.6 and below shell upload exploit. This is a variant of the flaw discovered in the same version by Murat Seker in March of 2021.

tags | exploit, shell
SHA-256 | 1436538566bc2047ab944ff8012333d763d61f1e1541f4ad7acb854d2806935a
Ubuntu Security Notice USN-4921-1
Posted Apr 21, 2021
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 4921-1 - It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code.

tags | advisory, arbitrary
systems | linux, ubuntu
advisories | CVE-2021-3410
SHA-256 | 87024ff6c191bb40811c1ca8de8bc0a3ac4ca491cbd4900fb45eb739b4934918
RemoteClinic 2 Cross Site Scripting
Posted Apr 21, 2021
Authored by nu11secur1ty

RemoteClinic 2 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2021-30044
SHA-256 | c45f8690b4b4bff71dc90d7b4222008bf3eb6231aed4384736a38bfc57fcbbcb
WordPress RSS For Yandex Turbo 1.29 Cross Site Scripting
Posted Apr 21, 2021
Authored by Himamshu Dilip Kulkarni

WordPress RSS for Yandex Turbo plugin version 1.29 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f33f759ff517707c00862118c43fe8866bee60549ed5f649f1b6c5df664f01b8
Red Hat Security Advisory 2021-1301-01
Posted Apr 21, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-1301-01 - The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2021-2163
SHA-256 | 15087b27679b08fe5d63785cade6bd64e49c1401cb1a1c6a4cac8fea0e8884e6
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close