exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 20 of 20 RSS Feed

Files Date: 2021-09-27

iOS 15.0 Nehelper Wifi Info Entitlement Check Bypass
Posted Sep 27, 2021
Authored by IllusionOfChaos | Site github.com

Zero day exploit for Nehelper Wifi Info on iOS 15.0. XPC endpoint com.apple.nehelper accepts user-supplied parameter sdk-version, and if its value is less than or equal to 524288, the com.apple.developer.networking.wifi-info entitlement check is skipped. This makes it possible for any qualifying application (e.g. possessing location access authorization) to gain access to Wifi information without the required entitlement. This happens in -[NEHelperWiFiInfoManager checkIfEntitled:] in /usr/libexec/nehelper.

tags | exploit
systems | apple, ios
SHA-256 | 0af5f880ff757d8f4ecf82631a976eb88cd98d6646578d823eeb66b9199ddf29
iOS 15.0 nehelper Enumeration
Posted Sep 27, 2021
Authored by IllusionOfChaos | Site github.com

Zero day exploit for nehelper on iOS 15.0 that allows any user-installed application to determine whether any application is installed on the device given its bundle ID.

tags | exploit, vulnerability
systems | apple, ios
SHA-256 | 375980bf93ee070923c3bb357ef6f80b43ca064d6099d8de7d730edb2ea93c70
iOS 15.0 Gamed Information Disclosure
Posted Sep 27, 2021
Authored by IllusionOfChaos | Site github.com

Zero day exploit for Gamed on iOS 15.0 that demonstrates information disclosure vulnerabilities.

tags | exploit, vulnerability, info disclosure
systems | apple, ios
SHA-256 | 064f75f646068bb009495ba2efc5724b31cd4cd7265da1713630bea9d23cab50
OpenSSH 8.8p1
Posted Sep 27, 2021
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: Various minor bug fixes and improvements.
tags | tool, encryption
systems | linux, unix, openbsd
SHA-256 | 4590890ea9bb9ace4f71ae331785a3a5823232435161960ed5fc86588f331fe9
Red Hat Security Advisory 2021-3666-01
Posted Sep 27, 2021
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2021-3666-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include denial of service, path sanitization, and use-after-free vulnerabilities.

tags | advisory, denial of service, javascript, vulnerability
systems | linux, redhat
advisories | CVE-2021-22930, CVE-2021-22931, CVE-2021-22939, CVE-2021-22940, CVE-2021-23343, CVE-2021-32803, CVE-2021-32804, CVE-2021-3672
SHA-256 | c3e88fe61108ab45d44ef8e7ffedeed0ae53649beffdf3ca315f12cedd7d9b64
Simple Attendance System 1.0 Authentication Bypass
Posted Sep 27, 2021
Authored by Richard Jones

Simple Attendance System version 1.0 authentication bypass exploit that adds an administrator.

tags | exploit
SHA-256 | e4a056c4bf0781532ad19c5a4655a2089555c71ce7492598d7a21cf841394ff6
WordPress Wappointment 2.2.4 Cross Site Scripting
Posted Sep 27, 2021
Authored by Renos Nikolaou

WordPress Wappointment plugin version 2.2.4 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 0ec2de8d6b3e7c213f925b6bf7c1a9f7fa2dd529191d328cb5129e5f0ca43245
Backdoor.Win32.Hupigon.afjk MVID-2021-0351 Directory Traversal
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Hupigon.afjk malware suffers from a directory traversal vulnerability.

tags | exploit
systems | windows
SHA-256 | d43696509b1d079ab11a9230faf15e7121c44dabdb639bf4f8f247da5e678d97
CMS Made Simple 2.1.3 Remote Code Execution
Posted Sep 27, 2021
Authored by Raed Ahsan

CMS Made Simple version 2.1.3 details on how to achieve remote code execution.

tags | exploit, remote, code execution
SHA-256 | 7b3459513dec24564aa30a512ffef2b5d1b795047278d892848f4efdab0eb7cc
Library System 1.0 SQL Injection
Posted Sep 27, 2021
Authored by Vinay Bhuria

Library System version 1.0 suffers from a remote SQL injection vulnerability. Original discovery of SQL injection in this version is attributed to Aitor Herrero in January of 2021.

tags | exploit, remote, sql injection
SHA-256 | eb854621eb94dfe51e7c8783a6ace3f21838ab76409df3a060deec311572353c
Backdoor.Win32.Hupigon.afjk MVID-2021-0350 Authentication Bypass / Code Execution
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Hupigon.afjk malware suffers from bypass and code execution vulnerabilities.

tags | exploit, vulnerability, code execution
systems | windows
SHA-256 | 3789a2c7b0f6ca3d18975f82d38fd4946423b730c882367fe89c3532b522752b
XAMPP 7.4.3 Privilege Escalation
Posted Sep 27, 2021
Authored by Salman Asad

XAMPP version 7.4.3 suffers from a local privilege escalation vulnerability.

tags | exploit, local
advisories | CVE-2020-11107
SHA-256 | 0f5c7877625783cce13ce18ad512bfe8d734d9d56724b3d2d03dd5e65b70849a
Backdoor.Win32.Hupigon.fjcd MVID-2021-0349 Unauthenticated Open Proxy
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Hupigon.fjcd malware suffers from an unauthenticated open proxy vulnerability.

tags | exploit
systems | windows
SHA-256 | 7de0bdc194e9a195fd15f5c530731f710ddb394ce0942d22da142be4871e92c4
Backdoor.Win32.RmtSvc.l MVID-2021-0348 Denial Of Service
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.RmtSvc.l malware suffers from a denial of service vulnerability.

tags | exploit, denial of service
systems | windows
SHA-256 | 7d8120cf6e5bc376034abd303564b5f0fc177eff78ec31c21e5e6838e9ec741b
Backdoor.Win32.Agent.aer MVID-2021-0347 Insecure Transit / Password Disclosure
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.aer malware suffers from an insecure transit vulnerability that allows for password disclosure.

tags | exploit
systems | windows
SHA-256 | 82907adb2d7ecb4c6e6ea602ffe8c252d98ed152468ed0e2f2d0c16894ca4ad2
Cisco Small Business RV130W 1.0.3.44 Injection
Posted Sep 27, 2021
Authored by Michael Alamoot

Cisco Small Business RV130W version 1.0.3.44 exploit that injects counterfeit routers.

tags | exploit
systems | cisco
SHA-256 | 9ed47dde50d98da582e5d59d6001b33156cd31eb809f23d7ab77bd1c630c5a6a
Ether MP3 CD Burner 1.3.8 Buffer Overflow
Posted Sep 27, 2021
Authored by Achilles

Ether MP3 CD Burner version 1.3.8 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
SHA-256 | 38045f1e0ebf2d489d9eb899bc1be79fc0401a50f3e8f8e83b9685b5d8606206
Backdoor.Win32.Agent.aer MVID-2021-0346 Denial Of Service
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Backdoor.Win32.Agent.aer malware suffers from a denial of service vulnerability.

tags | exploit, denial of service
systems | windows
SHA-256 | 6b8cd0c45d2977584957ed345ebad70c13f8edd94a144cc645cf10bf595862eb
Trojan-Downloader.Win32.VB.abb MVID-2021-0345 Insecure Permissions
Posted Sep 27, 2021
Authored by malvuln | Site malvuln.com

Trojan-Downloader.Win32.VB.abb malware suffers from an insecure permissions vulnerability.

tags | exploit, trojan
systems | windows
SHA-256 | 64e272a1e2097a25247ad10b5a8dcc3752c5438e31d03242bc1673fcdbc280e3
PASS-PHP 1.0 SQL Injection / Cross Site Scripting
Posted Sep 27, 2021
Authored by nu11secur1ty

PASS-PHP version 1.0 suffers from remote SQL injection and cross site scripting vulnerabilities.

tags | exploit, remote, php, vulnerability, xss, sql injection
SHA-256 | 1145a2df44f5b9647b8ad4207215a93abb5fe637fa0a66c4b4596511a4b1e5f5
Page 1 of 1
Back1Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close