exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 100 RSS Feed

Files

TS-2007-001-0.txt
Posted Jul 31, 2007
Authored by forloop, defaultroute

Template Security has discovered a serious denial of service vulnerability in the BlueCat Networks Adonis DNS/DHCP Appliance. When XHA is configured to place two Adonis servers in an active-passive pair to provide high availability, a remote attacker can transmit a single UDP datagram to crash the heartbeat control process. This can be used for example to create an active/active condition in the cluster pair.

tags | advisory, remote, denial of service, udp
SHA-256 | cc3a0e1f01e8c577869fec6643baaacbf4c0c356f0b25da7cd5cad08f003d024

Related Files

TSPlus 16.0.2.14 Insecure Permissions
Posted Aug 22, 2023
Authored by Carlo Di Dato

TSPlus version 16.0.2.14 suffers from an insecure permissions vulnerability.

tags | exploit
advisories | CVE-2023-31067
SHA-256 | 0bc7ecda382e75a1cb2b54690a396532c49dd66393a3842a9283c8bfaf166236
TSPlus 16.0.0.0 Insecure Permissions
Posted Aug 22, 2023
Authored by Carlo Di Dato

TSPlus version 16.0.0.0 suffers from an insecure permissions vulnerability.

tags | exploit
advisories | CVE-2023-31068
SHA-256 | 06f5da798bc1734c99952dd5665f7fc882b0e8d1c219d8e327e08d2824444cbb
TSPlus 16.0.0.0 Insecure Credential Storage
Posted Aug 22, 2023
Authored by Carlo Di Dato

TSPlus version 16.0.0.0 suffers from an insecure credential storage vulnerability.

tags | exploit
advisories | CVE-2023-31069
SHA-256 | 215f20ce0fd7976f257c178193251dfef5d9ab1191d503a59cbdd146d251811d
Time Slot Booking Calendar 1.8 Cross Site Scripting
Posted Jun 30, 2023
Authored by CraCkEr

Time Slot Booking Calendar version 1.8 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f65b274470cdaa58905697b946bb0b36c4806f9c1a414f504b6f854b7f020005
Piwigo 13.5.0 SQL Injection
Posted Apr 28, 2023
Authored by Rodolfo Tavares | Site tempest.com.br

Piwigo version 13.5.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2023-26876
SHA-256 | b4b2bf2bd02e5e6e2f24ce835e44e52d016f467252a6d79a30e013c6f3028a74
Train Scheduler App 1.0 Insecure Direct Object Reference
Posted Oct 31, 2022
Authored by Rohit Sharma

Train Scheduler App version 1.0 suffers from an insecure direct object reference vulnerability.

tags | exploit
advisories | CVE-2022-3774
SHA-256 | 35e0aca5c12fde1a197fcd41a91aeee4b905c913ce48905a08acc0913c03bbe7
WordPress WPvivid Backup Path Traversal
Posted Oct 4, 2022
Authored by Rodolfo Tavares | Site tempest.com.br

WordPress WPvivid Backup plugin versions prior to 0.9.76 suffer from a path traversal vulnerability.

tags | exploit
advisories | CVE-2022-2863
SHA-256 | fb090fe06b8107185b5b73bdfac52e984a5bd3987e4e8a14397734095d06addf
LiquidFiles 3.4.15 Cross Site Scripting
Posted May 19, 2022
Authored by Rodolfo Tavares | Site tempest.com.br

LiquidFiles version 3.4.15 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2021-30140
SHA-256 | 64fb0fffa85d330dbc47f539a594fa8fcad4c9362b419983c93474d08ba4e151
PHPIPAM 1.4.4 Cross Site Request Forgery / Cross Site Scripting
Posted May 19, 2022
Authored by Rodolfo Tavares | Site tempest.com.br

PHPIPAM version 1.4.4 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2021-46426
SHA-256 | 050c77ae0f13a5b4247218de44f8bf133ca516aae7da4d73aba802231bdde893
T-Soft E-Commerce 4 SQL Injection
Posted May 17, 2022
Authored by Alperen Ergel

T-Soft E-Commerce version 4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 45b5224650ea3cb883a0c405f3c4d76eef8cc2dbc8f3fb98282c4ea633d2e202
T-Soft E-Commerce 4 Cross Site Scripting
Posted May 17, 2022
Authored by Alperen Ergel

T-Soft E-Commerce version 4 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a38f9872c25051fb5d40689975a5a643292512cac28208caeaa677228ed3e251
T-Soft E-Commerce 4 Cross Site Request Forgery
Posted Sep 20, 2021
Authored by Alperen Ergel

T-Soft E-Commerce version 4 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | c6b8e63ffe9cd49eeb60a1fb0927f605b76c7e0f0c0526db27887b5438211ac3
Comprehensive Guide On TShark
Posted Apr 23, 2021
Authored by Jeenali Kothari | Site hackingarticles.in

This document is a guide on how to use tshark effectively to monitor and analyze traffic.

tags | paper
SHA-256 | b5f392c0a6f13e0c48407dcf564964d9098a9ac088cfac2258e29e1f74c4670c
Envira Gallery Lite 1.8.3.2 Cross Site Scripting
Posted Jan 13, 2021
Authored by Rodolfo Tavares | Site tempest.com.br

Envira Gallery Lite edition version 1.8.3.2 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2020-35581, CVE-2020-35582
SHA-256 | 9dbf149ef3ee66457f73ea7147ed74161ff3ef6881909b863f14b4bf54649b7c
Typesetter CMS 5.1 Remote Code Execution
Posted Oct 7, 2020
Authored by Rodolfo Tavares | Site tempest.com.br

Typesetter version 5.1 is vulnerable to code execution via /index.php/Admin/Uploaded. An attacker can exploit this by uploading a zip that contains a malicious php file inside. After extracting the zip file containing the malicious php file, it is possible to execute commands on the target operation system.

tags | advisory, php, code execution
advisories | CVE-2020-25790
SHA-256 | ee974c9d37c8aba758fd4db3a34e859ee9e9a7a9e7db287f6d35e858f330de34
GilaCMS 1.11.5 Cross Site Request Forgery / Cross Site Scripting
Posted Jun 23, 2020
Authored by Rodolfo Tavares | Site tempest.com.br

GilaCMS version 1.11.5 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2019-20803, CVE-2019-20804
SHA-256 | 6603d87a861a3d845fa61f9b588c6b86e0c8fe070114880b2f66b4cd804da8df
Avast Secure Browser 76.0.1659.101 Local Privilege Escalation
Posted Mar 21, 2020
Authored by Silton Santos

A local privilege escalation issue was discovered in Avast Secure Browser version 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates.

tags | advisory, local
advisories | CVE-2019-17190
SHA-256 | c3807d4734d35255ec28f3968e435a787e351216fcadf4013c873c8d1ea9df67
Piwigo 2.9.5 Cross Site Request Forgery / Cross Site Scripting
Posted Sep 13, 2019
Authored by Rodolfo Tavares

Piwigo version 2.9.5 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2019-13363, CVE-2019-13364
SHA-256 | 8a705d66a11dea3ced8ff1ddbb628df03886926a4d88a4506f71c1bceda77cb7
Terminal Services Manager 3.2.1 Denial Of Service
Posted May 23, 2019
Authored by Alejandra Sanchez

Terminal Services Manager version 3.2.1 denial of service proof of concept exploit.

tags | exploit, denial of service, proof of concept
SHA-256 | 20930ea7270b48fd4bd7377a0b79548a0455c7a5731a33bb0cdcaf66aee17b80
Technical Support Juxiang Network China 1.0 SQL Injection
Posted Dec 31, 2018
Authored by KingSkrupellos

Technical Support Juxiang Network China version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 38f642bca055cb91ae9426e8b412b4577b486240a0908f709bf79885f85e92ea
Terminal Services Manager 3.1 Local Buffer Overflow
Posted Dec 27, 2018
Authored by bzyo

Terminal Services Manager version 3.1 SEH local buffer overflow exploit.

tags | exploit, overflow, local
SHA-256 | ef05c13c249019baff4c01b24665030f69325150807beba41da28401fca3cfea
G DATA TOTAL SECURITY 25.4.0.3 Active-X Buffer Overflow
Posted Jul 13, 2018
Authored by Felipe Xavier Oliveira

G DATA TOTAL SECURITY version 25.4.0.3 suffers from an active-x buffer overflow vulnerability.

tags | exploit, overflow, activex
advisories | CVE-2018-10018
SHA-256 | a4a9b35e2dd08d915f0c7853b6318dcc7ae9080e1e6d5e6db10980d7390b81e0
Total AV 4.6.19 Insecure Permissions
Posted Jul 13, 2018
Authored by Felipe Xavier Oliveira

A vulnerability allows local attackers to escalate privilege on TotalAV versions 4.1.7 through 4.6.19 because of weak "C:\Program Files\TotalAV" permissions. The specific flaw exists within the access control that is set and modified during the installation of the product. The product sets weak access control restrictions. An attacker can leverage this vulnerability to execute arbitrary code under the context of Administrator, the IUSR account, or SYSTEM.

tags | exploit, arbitrary, local
advisories | CVE-2018-5313
SHA-256 | 7ddb47fa9650b8d0c8373db8166f2ded014751591383842dbb2ccdcaaeebaa73
ISS For Business 14.0.1400.2029 Blue Screen Of Death
Posted Jul 13, 2018
Authored by Felipe Xavier Oliveira

In MicroWorld eScan Internet Security Suite (ISS) for Business version 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).

tags | advisory, denial of service
advisories | CVE-2018-10018, CVE-2018-10098
SHA-256 | 8b95bb49aed9a1a93908ec4399e0088c6836bf8eba34be94d0cccbce2da183db
Panda Global Security 17.0.1 NULL DACL Grants Full Access
Posted Mar 8, 2018
Authored by Felipe Xavier Oliveira

Panda Global Security version 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through the use of an insecurely created named pipe.

tags | exploit, denial of service, local
advisories | CVE-2018-6322
SHA-256 | 3d04c6e271055eec4d1aa92ac83833674c1a67f99b109e56f8a5e20b0657c1bb
Page 1 of 4
Back1234Next

File Archive:

November 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    1 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    0 Files
  • 5
    Nov 5th
    0 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    219 Files
  • 14
    Nov 14th
    19 Files
  • 15
    Nov 15th
    66 Files
  • 16
    Nov 16th
    38 Files
  • 17
    Nov 17th
    9 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    11 Files
  • 22
    Nov 22nd
    56 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    36 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    14 Files
  • 28
    Nov 28th
    30 Files
  • 29
    Nov 29th
    35 Files
  • 30
    Nov 30th
    25 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close