exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 365 RSS Feed

Files Date: 2022-02-01 to 2022-02-28

Simple Real Estate Portal System 1.0 SQL Injection
Posted Feb 21, 2022
Authored by nu11secur1ty

Simple Real Estate Portal System version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 2a175a101b412ad22ce92495b58ffcb40e5ea3e33025cd72c7dfc87ffad16377
Microweber 1.2.11 Shell Upload
Posted Feb 21, 2022
Authored by Chetanya Sharma

Microweber version 1.2.11 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
advisories | CVE-2022-0557
SHA-256 | 0f6099f5333136e7ed26b16e612cd8174391ba44ec5c5315299e6e968e78e18a
Dbltek GoIP GHSFVT-1.1-67-5 Local File Inclusion
Posted Feb 21, 2022
Authored by Lassi Korhonen, Valtteri Lehtinen

Dbltek GoIP with firmware version GHSFVT-1.1-67-5 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 0d6bacc2c1374df5d970bb3cd46b2c784a546df1614076f108665a82cba4a43f
Red Hat Security Advisory 2022-0582-01
Posted Feb 21, 2022
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2022-0582-01 - Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Issues addressed include HTTP request smuggling, HTTP response splitting, code execution, denial of service, information leakage, and spoofing vulnerabilities.

tags | advisory, web, denial of service, spoof, vulnerability, code execution, ruby
systems | linux, redhat
advisories | CVE-2019-15845, CVE-2019-16201, CVE-2019-16254, CVE-2019-16255, CVE-2020-10663, CVE-2020-10933, CVE-2020-25613, CVE-2020-36327, CVE-2021-28965, CVE-2021-31799, CVE-2021-31810, CVE-2021-32066, CVE-2021-41817, CVE-2021-41819
SHA-256 | 28f434c8a7e0c5a9a457c78e1d0a72539ecb56d9a3673853dd0aa3595f619eda
FileCloud 21.2 Cross Site Request Forgery
Posted Feb 21, 2022
Authored by Masashi Fujiwara

FileCloud version 21.2 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
advisories | CVE-2022-25241
SHA-256 | 416ed4585ffdeade05c15223afc7b591ef0cc08552298fcd8b219cac992f1ebf
Datarobot Remote Code Execution
Posted Feb 21, 2022
Authored by Mike Coers

Datarobot suffers from a remote code execution vulnerability.

tags | advisory, remote, code execution
advisories | CVE-2021-45414
SHA-256 | 655be82d858b050310a87d53a8e33454703d09ce4323f8de6be4263ffe788843
WordPress Perfect Survey 1.5.1 SQL Injection
Posted Feb 21, 2022
Authored by Ron Jost

WordPress Perfect Survey plugin version 1.5.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2021-24762
SHA-256 | ab5b6dcc9f080add826ddde39b1034b8a2169f9e05ade5e04cba6ab0dd330869
WordPress WP User Frontend 3.5.25 SQL Injection
Posted Feb 21, 2022
Authored by Ron Jost

WordPress WP User Frontend plugin version 3.5.25 suffers from an authenticated remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2021-25076
SHA-256 | 280867a4c60d20510ff5bcaa423c881cbcd213e1b2b74568a593019331132f17
Red Hat Security Advisory 2022-0581-01
Posted Feb 21, 2022
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2022-0581-01 - Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Issues addressed include HTTP request smuggling, HTTP response splitting, code execution, denial of service, information leakage, and spoofing vulnerabilities.

tags | advisory, web, denial of service, spoof, vulnerability, code execution, ruby
systems | linux, redhat
advisories | CVE-2019-15845, CVE-2019-16201, CVE-2019-16254, CVE-2019-16255, CVE-2020-10663, CVE-2020-10933, CVE-2020-25613, CVE-2020-36327, CVE-2021-28965, CVE-2021-31799, CVE-2021-31810, CVE-2021-32066, CVE-2021-41817, CVE-2021-41819
SHA-256 | 8bd21cf01e10e7a947db8efca057a501595b8383a816b9f497a90e17a13ebc45
Thinfinity VirtualUI 2.5.26.2 Information Disclosure
Posted Feb 21, 2022
Authored by Daniel Morales

Thinfinity VirtualUI version 2.5.26.2 suffers from an information disclosure vulnerability.

tags | exploit, info disclosure
advisories | CVE-2021-46354
SHA-256 | 2b19df6335cfc9aa814e3c77fff5405550b9e652464edcbb2f4a2198d44c4ca2
Thinfinity VirtualUI 2.5.41.0 IFRAME Injection
Posted Feb 21, 2022
Authored by Daniel Morales

Thinfinity VirtualUI version 2.5.41.0 suffers from an iframe injection vulnerability.

tags | exploit
advisories | CVE-2021-45092
SHA-256 | 283c85287dddc71af90a100ee3df9c121378aa5bca5bd0c6921c262fe57f8e4a
Auto Spare Parts Management 1.0 SQL Injection
Posted Feb 21, 2022
Authored by nu11secur1ty

Auto Spare Parts Management version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 30d2f6c411784c3d31a4f2a68f89253ed00f4b05363894cf28982b8ab866391c
HMA VPN 5.3 Unquoted Service Path
Posted Feb 21, 2022
Authored by Saud Alenazi

HMA VPN version 5.3 suffers from an unquoted service path vulnerability.

tags | exploit
SHA-256 | fc3746e5e4d9467b9c73f54d58ba3cb675ceafeb9154939efe86c570c653aae5
Microsoft Gaming Services 2.52.13001.0 Unquoted Service Path
Posted Feb 21, 2022
Authored by Johto Robbie

Microsoft Gaming Services version 2.52.13001.0 suffers from an unquoted service path vulnerability.

tags | exploit
SHA-256 | 79139fdf3f5e6f9881454cf1de4ebaa7d172abaf459df0807afef041b5d9a6ad
Cab Management System 1.0 SQL Injection
Posted Feb 21, 2022
Authored by Alperen Ergel

Cab Management System version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c54a778ac6cac7cf0947d6a7afb026a8c6339c431312f32c1346da1b9e5231db
Cab Management System 1.0 Remote Code Execution
Posted Feb 21, 2022
Authored by Alperen Ergel

Cab Management System version 1.0 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
SHA-256 | 771891c9014d619ea4cab2be545d0859bab5c615100aa07d5a40c542c6895aae
Collabfiltrator 2.1
Posted Feb 21, 2022
Authored by Ryan Griffin, Frank Scarpella, Jared McLaren, Adam Logue | Site github.com

Collabfiltrator is a tool to exfiltrate blind remote code execution output over DNS via Burp Collaborator.

tags | tool, remote, code execution, rootkit
systems | unix
SHA-256 | e4f2c5b6b0aea01cabdd0c7e8cce96dca706d60a5b08960cdab94118b9c52dfe
Ubuntu Security Notice USN-5295-1
Posted Feb 18, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5295-1 - It was discovered that the Packet network protocol implementation in the Linux kernel contained a double-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Jann Horn discovered a race condition in the Unix domain socket implementation in the Linux kernel that could result in a read-after-free. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

tags | advisory, denial of service, arbitrary, kernel, local, protocol
systems | linux, unix, ubuntu
advisories | CVE-2021-22600, CVE-2021-4083, CVE-2021-4155, CVE-2022-0330, CVE-2022-22942
SHA-256 | b547d8a973a224e901b06eaeedecd20d12b7bfbede9c1be88b6689532cb1a805
WordPress MasterStudy LMS 2.7.5 Account Creation
Posted Feb 18, 2022
Authored by numan turle

WordPress MasterStudy LMS plugin version 2.7.5 suffers from a missing access control allowing an unauthenticated party the ability to create an administrative account.

tags | exploit
advisories | CVE-2022-0441
SHA-256 | a3a490fa31272315dc3b33abac3a970e548d08d2ce2376d9748f5e401a62604f
WordPress UpdraftPlus 1.22.2 Backup Disclosure
Posted Feb 18, 2022
Authored by Marc Montpass | Site wordfence.com

WordPress UpdraftPlus versions 1.16.7 through 1.22.2 suffer from a backup disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2022-0633
SHA-256 | b497726806b3d3cd3a57bcd3b91fab0d6c64ec521a48183b3477b06789862f15
Ubuntu Security Notice USN-5292-3
Posted Feb 18, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5292-3 - USN-5292-1 fixed several vulnerabilities in snapd. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. James Troup discovered that snap did not properly manage the permissions for the snap directories. A local attacker could possibly use this issue to expose sensitive information. Ian Johnson discovered that snapd did not properly validate content interfaces and layout paths. A local attacker could possibly use this issue to inject arbitrary AppArmor policy rules, resulting in a bypass of intended access restrictions. The Qualys Research Team discovered that snapd did not properly validate the location of the snap-confine binary. A local attacker could possibly use this issue to execute other arbitrary binaries and escalate privileges. The Qualys Research Team discovered that a race condition existed in the snapd snap-confine binary when preparing a private mount namespace for a snap. A local attacker could possibly use this issue to escalate privileges and execute arbitrary code.

tags | advisory, arbitrary, local, vulnerability
systems | linux, ubuntu
advisories | CVE-2021-3155, CVE-2021-4120, CVE-2021-44730, CVE-2021-44731
SHA-256 | 23fb2407472813360c266bf4444366a9b1f39826d88b86b3b54675092a32d4ec
WordPress dzs-zoomsounds 6.60 Shell Upload
Posted Feb 18, 2022
Authored by Overthinker1877

WordPress dzs-zoomsounds plugin version 6.60 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 6e96492b3bf0c53feb2e28da2e7826b4b660705ff00d0ce838e33bbfbb07bf95
Ubuntu Security Notice USN-5292-2
Posted Feb 18, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5292-2 - USN-5292-1 fixed vulnerabilities in snapd. This update provides the corresponding update for the riscv64 architecture. James Troup discovered that snap did not properly manage the permissions for the snap directories. A local attacker could possibly use this issue to expose sensitive information.

tags | advisory, local, vulnerability
systems | linux, ubuntu
advisories | CVE-2021-3155, CVE-2021-4120, CVE-2021-44730, CVE-2021-44731
SHA-256 | 0c6bd21fafc633dfdaa09088d54dc04cc7a81354d0f9a2be6b57f8f4dccd6efa
Fortinet Fortimail 7.0.1 Cross Site Scripting
Posted Feb 18, 2022
Authored by Braiant Giraldo Villa

Fortinet Fortimail version 7.0.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2021-43062
SHA-256 | 7f8798b7aa7700d879a636522b5f36adeafdc2272b48d2974f728dabead950cd
Ubuntu Security Notice USN-5294-1
Posted Feb 18, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5294-1 - It was discovered that the Packet network protocol implementation in the Linux kernel contained a double-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Szymon Heidrich discovered that the USB Gadget subsystem in the Linux kernel did not properly restrict the size of control requests for certain gadget types, leading to possible out of bounds reads or writes. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

tags | advisory, denial of service, arbitrary, kernel, local, protocol
systems | linux, ubuntu
advisories | CVE-2021-22600, CVE-2021-39685, CVE-2021-4083, CVE-2021-4155, CVE-2021-4202, CVE-2021-43975, CVE-2022-0330, CVE-2022-22942
SHA-256 | 1366df82d8fcd6815d5088e53ffe7f4c0a5200426d7806e8827105451bd46108
Page 4 of 15
Back23456Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close