seeing is believing
Showing 1 - 25 of 39,179 RSS Feed

Exploit Files

Automated Logic WebCTRL 6.5 Unrestricted File Upload Remote Code Execution
Posted Aug 23, 2017
Authored by LiquidWorm | Site zeroscience.mk

Automated Logic WebCTRL version 6.5 suffers from an unrestricted file upload vulnerability that allows for remote code execution.

tags | exploit, remote, code execution, file upload
advisories | CVE-2017-9650
MD5 | dfbd662ecb79e969664c3cfd3b845d91
Automated Logic WebCTRL 6.1 Path Traversal Arbitrary File Write
Posted Aug 23, 2017
Authored by LiquidWorm | Site zeroscience.mk

Automated Logic WebCTRL version 6.1 suffers from path traversal and arbitrary file write vulnerabilities.

tags | exploit, arbitrary, vulnerability
advisories | CVE-2017-9640
MD5 | ba74d7e72b8d250b3eb5121245e82a5f
Automated Logic WebCTRL 6.5 Insecure File Permissions Privilege Escalation
Posted Aug 23, 2017
Authored by LiquidWorm | Site zeroscience.mk

Automated Logic WebCTRL version 6.5 suffers from an insecure file permission privilege escalation vulnerability.

tags | exploit
advisories | CVE-2017-9644
MD5 | bfe85c9a0561b977ce1f85fffe2a9011
Progress Sitefinity 9.1 XSS / Session Management / Open Redirect
Posted Aug 23, 2017
Authored by Siddhartha Tripathy, Mingshuo Li | Site sec-consult.com

Progress Sitefinity version 9.1 suffers from cross site scripting, broken session management, and open redirection vulnerabilities.

tags | exploit, vulnerability, xss
MD5 | 4afe3027dc44e61418fd14ecec494013
WebClientPrint Processor 2.0.15.109 Unauthorized Proxy Modification
Posted Aug 23, 2017
Site redteam-pentesting.de

RedTeam Pentesting discovered that attackers can configure a proxy host and port to be used when fetching print jobs with WebClientPrint Processor (WCPP). This proxy setting may be distributed via specially crafted websites and is set without any user interaction as soon as the website is accessed. Version 2.0.15.109 is affected.

tags | exploit
MD5 | 65bcf60f4004c2179e69c921c1d0d32e
WebClientPrint Processor 2.0.15.109 Updates Remote Code Execution
Posted Aug 23, 2017
Site redteam-pentesting.de

RedTeam Pentesting discovered that rogue updates trigger a remote code execution vulnerability in WebClientPrint Processor (WCPP). These updates may be distributed through specially crafted websites and are processed without any user interaction as soon as the website is accessed. However, the browser must run with administrative privileges. Version 2.0.15.109 is affected.

tags | exploit, remote, code execution
MD5 | 07b4b9ff9c5b4404c6ff6a8c28c57180
WebClientPrint Processor 2.0.15.109 TLS Validation
Posted Aug 23, 2017
Site redteam-pentesting.de

RedTeam Pentesting discovered that WebClientPrint Processor (WCPP) does not validate TLS certificates when initiating HTTPS connections. Thus, a man-in-the-middle attacker may intercept and/or modify HTTPS traffic in transit. This may result in a disclosure of sensitive information and the integrity of printed documents cannot be guaranteed. Version 2.0.15.109 is affected.

tags | exploit, web
MD5 | 2ab94fee77e67ce1fcb57508ff026f8e
WebClientPrint Processor 2.0.15.190 Print Jobs Remote Code Execution
Posted Aug 23, 2017
Site redteam-pentesting.de

WebClientPrint Processor version 2.0.15.109 suffers from a remote code execution vulnerability via print jobs.

tags | exploit, remote, code execution
MD5 | f0de493e09096c617a8989b48f1d528d
Backdrop CMS 1.7.1 Cross Site Scripting
Posted Aug 23, 2017
Authored by Manuel Garcia Cardenas

Backdrop CMS versions 1.7.1 and below suffer from a persistent cross site scripting vulnerability.

tags | exploit, xss
MD5 | 3a5a51d7bbe3c89f83373c95b27188e1
Windows Escalate UAC Protection Bypass (Via COM Handler Hijack)
Posted Aug 22, 2017
Authored by b33f, OJ Reeves, Matt Nelson | Site metasploit.com

This Metasploit module will bypass Windows UAC by creating COM handler registry entries in the HKCU hive. When certain high integrity processes are loaded, these registry entries are referenced resulting in the process loading user-controlled DLLs. These DLLs contain the payloads that result in elevated sessions. Registry key modifications are cleaned up after payload invocation. This Metasploit module requires the architecture of the payload to match the OS, but the current low-privilege Meterpreter session architecture can be different. If specifying EXE::Custom your DLL should call ExitProcess() after starting your payload in a separate process. This Metasploit module invokes the target binary via cmd.exe on the target. Therefore if cmd.exe access is restricted, this module will not run correctly.

tags | exploit, registry
systems | windows
MD5 | 73fea9d04345bcd15b0dc980da1ce0e1
VMware VDP Known SSH Key
Posted Aug 22, 2017
Authored by phroxvs | Site metasploit.com

VMware vSphere Data Protection appliances 5.5.x through 6.1.x contain a known ssh private key for the local user admin who is a sudoer without password.

tags | exploit, local
advisories | CVE-2016-7456
MD5 | 78afbce4852e1d46d51d532f9a44d891
IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution
Posted Aug 22, 2017
Authored by securiteam | Site metasploit.com

This Metasploit module exploits an unauthenticated remote PHP code execution vulnerability in IBM OpenAdmin Tool included with IBM Informix versions 11.5, 11.7, and 12.1. The 'welcomeServer' SOAP service does not properly validate user input in the 'new_home_page' parameter of the 'saveHomePage' method allowing arbitrary PHP code to be written to the config.php file. The config.php file is executed in most pages within the application, and accessible directly via the web root, resulting in code execution. This Metasploit module has been tested successfully on IBM OpenAdmin Tool 3.14 on Informix 12.10 Developer Edition (SUSE Linux 11) virtual appliance.

tags | exploit, remote, web, arbitrary, root, php, code execution
systems | linux, suse
advisories | CVE-2017-1092
MD5 | b78839adcfa2b9b750dba9d03fc684b8
Disk Pulse Enterprise 9.9.16 Buffer Overflow
Posted Aug 22, 2017
Authored by Anurag Srivastava

Disk Pulse Enterprise version 9.9.16 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
MD5 | 26d38ff2408eafa19af8bb94079c203d
Disk Sorter Enterprise 9.9.12 Buffer Overflow
Posted Aug 22, 2017
Authored by Anurag Srivastava

Disk Sorter Enterprise version 9.9.12 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
MD5 | 6961e113a3ac24650472c1e61138e4ec
Sync Breeze Enterprise 9.9.16 Buffer Overflow
Posted Aug 22, 2017
Authored by Anurag Srivastava

Sync Breeze Enterprise version 9.9.16 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
MD5 | 649a8043481d1251c34c53ffd21bb3f3
Apache2Triad 1.5.4 CSRF / XSS / Session Fixation
Posted Aug 21, 2017
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

Apache2Triad version 1.5.4 suffers from session fixation, cross site request forgery, and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2017-12965, CVE-2017-12970, CVE-2017-12971
MD5 | 5f84ac13f6c4c57a37441585b0a25c8b
Joomla Ajax Quiz 1.8 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

Joomla Ajax Quiz component version 1.8 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | d4ed9a9f7d426040140918b7d30f0178
PHP Coupon Script 6.0 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

PHP Coupon Script version 6.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 4d5d302c3fc2243a45c1479db0daa87e
Bitcoin / Dogecoin Mining 1.0 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

Bitcoin / Dogecoin version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | ad2c57789c7661321778bc76e64ace95
Microsoft Edge Chakra chakra!Js::GlobalObject Integer Overflow
Posted Aug 21, 2017
Authored by He Xiaoxiao, Huang Anwen

Microsoft Edge Chakra suffers from a chakra!Js::GlobalObject internet overflow vulnerability.

tags | exploit, overflow
advisories | CVE-2017-8641
MD5 | 27bc98a6edda5dac2e242517a2a0c314
Joomla Twitch Tv 1.1 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

Joomla Twitch Tv component version 1.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | fe76eab51bcc20149a0edbcc4d23b498
PHP-Lance 1.52 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

PHP-Lance version 1.52 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | e8d2d0097ba26f9be292396680c25676
PHPMyWind 5.3 Cross Site Scripting
Posted Aug 21, 2017

PHPMyWind version 5.3 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2017-12984
MD5 | 9c51d3db1a86e6f4a139731d8a2044c0
PHP Jokesite 2.0 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

PHP Jokesite version 2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 74908aabc66977a18175cabb83584b15
TP-Link TD-W8901G Default Credentials / Authentcation Bypass
Posted Aug 20, 2017
Authored by Vuppala Dhanunjaya

TP-Link TD-W8901G suffers from default credential and authentication bypass vulnerabilities.

tags | exploit, vulnerability, info disclosure
MD5 | 2b06bcd4f13729f6039bab7de4d929b7
Page 1 of 1,568
Back12345Next

File Archive:

August 2017

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    20 Files
  • 2
    Aug 2nd
    30 Files
  • 3
    Aug 3rd
    20 Files
  • 4
    Aug 4th
    17 Files
  • 5
    Aug 5th
    4 Files
  • 6
    Aug 6th
    2 Files
  • 7
    Aug 7th
    15 Files
  • 8
    Aug 8th
    18 Files
  • 9
    Aug 9th
    10 Files
  • 10
    Aug 10th
    24 Files
  • 11
    Aug 11th
    10 Files
  • 12
    Aug 12th
    3 Files
  • 13
    Aug 13th
    3 Files
  • 14
    Aug 14th
    10 Files
  • 15
    Aug 15th
    16 Files
  • 16
    Aug 16th
    18 Files
  • 17
    Aug 17th
    15 Files
  • 18
    Aug 18th
    17 Files
  • 19
    Aug 19th
    15 Files
  • 20
    Aug 20th
    11 Files
  • 21
    Aug 21st
    15 Files
  • 22
    Aug 22nd
    15 Files
  • 23
    Aug 23rd
    13 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close