what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 54,332 RSS Feed

Exploit Files

Restaurant POS 1.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Restaurant POS version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 1efe1a827da05e9054d6424d0c6cbeffd061cb7a7b523985c9f815859c5ded7a
Responsive Binary mlm 3.2.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Responsive Binary mlm version 3.2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | 7832158bdfb6f25736475de94f715b561965469ceb63c7f42c224430b50843df
Responsive Billing sw System 3.2.0 SQL Injection
Posted Sep 26, 2024
Authored by indoushka

Responsive Billing sw System version 3.2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | a0219dae7fd1734f734512e67150e374366e1b2cf6be0d9351c5231f163d3f5a
PHP SPM 1.0 WYSIWYG Code Injection
Posted Sep 26, 2024
Authored by indoushka

PHP SPM version 1.0 suffers from a WYSIWYG code injection vulnerability.

tags | exploit, php
SHA-256 | 536b68dcbe9d4246c7b010d149de6d84d7dd1692847cf3ff869f37c679492ff7
PHP ACRSS 1.0 WYSIWYG Code Injection
Posted Sep 26, 2024
Authored by indoushka

PHP ACRSS version 1.0 suffers from a WYSIWYG code injection vulnerability.

tags | exploit, php
SHA-256 | 4007e9d326a3fe6cb1abc611dc7edabd1018b4749c72ecb7f637d013b3571243
ABB Cylon Aspect 3.07.00 Remote Code Execution
Posted Sep 25, 2024
Authored by LiquidWorm | Site zeroscience.mk

The ABB Cylon Aspect version 3.07.00 BMS/BAS controller suffers from an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the host HTTP GET parameter called by networkDiagAjax.php script.

tags | exploit, web, arbitrary, shell, php
advisories | CVE-2023-0636
SHA-256 | 8123a5d0a4c6fa336d0b765079abb5168cf0f686b24baa715db1e55915f315fe
PHP SPM 1.0 Code Injection
Posted Sep 25, 2024
Authored by indoushka

PHP SPM version 1.0 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 42eadddca12393ee271fabcce4e022f9356f7034e6fb3c8f39890de24c8c2b65
PHP ACRSS 1.0 Code Injection
Posted Sep 25, 2024
Authored by indoushka

PHP ACRSS version 1.0 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 9a020e5f43760ba811c1702f617a4ccf04426dfe0e6f358f368a57c7bd6f3a92
Online mcq System 1.0 Cross Site Scripting
Posted Sep 25, 2024
Authored by indoushka

Online mcq System version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 9812280a7f199cadf92edba4b315443af80a2d51f9eb3e18e448c7ad4e24f4a3
Online Job Search System 1.0 Arbitrary File Upload
Posted Sep 25, 2024
Authored by indoushka

Online Job Search System version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 25f5aa2a29c64ab981939ce3c1c10082aa1a07beb7098128132b5921c035bc9d
Online Flight Booking System 1.0 Arbitrary File Upload
Posted Sep 25, 2024
Authored by indoushka

Online Flight Booking System version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | cbda91dc01c92da5a98f256f2b262f13fd4937433fae73274fba8113fbbc7648
Multi Branch School Management System 3.5 Backup Disclosure
Posted Sep 25, 2024
Authored by indoushka

Multi Branch School Management System version 3.5 suffers from a backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | b4c3fb3408f8d7a80baf2b5ec0b035520c60a8b287134c61abe01863834639ea
Complete Multi Hospital Management System 1.0 Backup Disclosure
Posted Sep 25, 2024
Authored by indoushka

Complete Multi Hospital Management System version 1.0 suffers from a backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | e760cf3c5b44d7d8984817fcf92204fd9912a026b5d02720406cc72f12ac70ed
Traccar 5.1 Code Injection
Posted Sep 25, 2024
Authored by indoushka

Traccar version 5.1 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 5595b2f52c8ca128698035a80627f56d2e0f69a1d0d431ac663d369417828fbb
ABB Cylon Aspect 3.08.01 Remote Code Execution
Posted Sep 24, 2024
Authored by LiquidWorm | Site zeroscience.mk

ABB Cylon Aspect version 3.08.01 BMS/BAS controller suffers from a remote code execution vulnerability. The vulnerable uploadFile() function in bigUpload.php improperly reads raw POST data using the php://input wrapper without sufficient validation. This data is passed to the fwrite() function, allowing arbitrary file writes. Combined with an improper sanitization of file paths, this leads to directory traversal, allowing an attacker to upload malicious files to arbitrary locations. Once a malicious file is written to an executable directory, an authenticated attacker can trigger the file to execute code and gain unauthorized access to the building controller.

tags | exploit, remote, arbitrary, php, code execution
advisories | CVE-2024-6298
SHA-256 | da48953d86e3e633d210a21a755ad55098b6f12fdc0866504b37f9828d654fc5
ABB Cylon Aspect 3.08.01 Arbitrary File Deletion
Posted Sep 24, 2024
Authored by LiquidWorm | Site zeroscience.mk

ABB Cylon Aspect version 3.08.01 MS/BAS controller suffers from an arbitrary file deletion vulnerability. Input passed to the file parameter in databasefiledelete.php is not properly sanitized before being used to delete files. This can be exploited by an unauthenticated attacker to delete files with the permissions of the web server using directory traversal sequences passed within the affected POST parameter.

tags | exploit, web, arbitrary, php
advisories | CVE-2024-6209
SHA-256 | 5dbc986f6601c3bda5e54887231d2fa175f92f4f522e9ef2bc6cd9d2c722d9d9
Traccar 5.12 Remote Code Execution
Posted Sep 24, 2024
Authored by Naveen Sunkavally, Michael Heinzl, yiliufeng168 | Site metasploit.com

This Metasploit module exploits a remote code execution vulnerability in Traccar versions 5.1 through 5.12. Remote code execution can be obtained by combining path traversal and an unrestricted file upload vulnerabilities. By default, the application allows self-registration, enabling any user to register an account and exploit the issues. Moreover, the application runs by default with root privileges, potentially resulting in a complete system compromise. This Metasploit module, which should work on any Red Hat-based Linux system, exploits these issues by adding a new cronjob file that executes the specified payload.

tags | exploit, remote, root, vulnerability, code execution, file upload
systems | linux, redhat
advisories | CVE-2024-24809, CVE-2024-31214
SHA-256 | 0bc1add3ef020b8c6e70e1d2ec3bfd3d9c59d68531db58229710061c08ef8c2e
Apple iOS 17.2.1 Screen Time Passcode Retrieval / Mitigation Bypass
Posted Sep 24, 2024
Authored by SivertPL

A mitigation bypass / privilege escalation flaw has been discovered in Apple's iOS Screen Time functionality, granting one access to modify the restrictions. It allows a local attacker to acquire the Screen Time Passcode by bypassing the anti-bruteforce protections on the four-digit Passcode, and in consequence gaining total control over Screen Time (Parental Control) settings. Versions lower than 18 are affected.

tags | exploit, local, bypass
systems | apple, ios
SHA-256 | 75666d1dc71fb63eadc1180b8fde8bebebfa673977a37f948bb5e8bd009bd6f8
Netman 204 4.05 SQL Injection / Unauthenticated Password Reset
Posted Sep 24, 2024
Authored by T. Weber, S. Dietz, D. Blagojevic | Site cyberdanube.com

Netman 204 version 4.05 suffers from remote SQL injection and unauthenticated password reset vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
advisories | CVE-2024-8877, CVE-2024-8878
SHA-256 | 9c87235443244a564a179cec6442609a57be8b1bcb3c5c9b1b6a264fe45368e8
Elaine's Realtime CRM Automation 6.18.17 Cross Site Scripting
Posted Sep 24, 2024
Authored by Haythem Arfaoui

Elaine's Realtime CRM Automation version 6.18.17 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2024-42831
SHA-256 | 4b49b8787ad3de23e5938175a4235b63ac86724d249f7e14581b817cf1993384
PHP ACRSS 1.0 Cross Site Request Forgery
Posted Sep 24, 2024
Authored by indoushka

PHP ACRSS version 1.0 suffers from a cross site request forgery vulnerability.

tags | exploit, php, csrf
SHA-256 | eae5bd10e0e3c0cb032d26f40702865ee30f2c293fef75064a152ed20917169e
Reservation Management System 1.0 Backup Disclosure
Posted Sep 24, 2024
Authored by indoushka

Reservation Management System version 1.0 suffers from a backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 3fdb31b63dd3dffcc359c8fe22cdbfc2692c268e17a6a1cc41302fd995ff1353
Rail Pass Management System 1.0 Insecure Settings
Posted Sep 24, 2024
Authored by indoushka

Rail Pass Management System version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | 9b616ee5d482ef2ecfbd81ee24873eba218fd61e3ce0cb54a3da94dd2290af0a
PreSchool Enrollment System 1.0 Insecure Settings
Posted Sep 24, 2024
Authored by indoushka

PreSchool Enrollment System version 1.0 suffers from an ignored default credential vulnerability.

tags | exploit
SHA-256 | 1d66855ad31d525ff1cd0aa67b987d6891d1fdd6e724a205e60af70bec92a07d
PHP SPM 1.0 Cross Site Request Forgery
Posted Sep 24, 2024
Authored by indoushka

PHP SPM version 1.0 suffers from a cross site request forgery vulnerability.

tags | exploit, php, csrf
SHA-256 | 25519b806495665c5736468ca62dfab30a516399cf5e67d1acce326963a8b403
Page 2 of 2,174
Back12345Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    38 Files
  • 24
    Sep 24th
    65 Files
  • 25
    Sep 25th
    24 Files
  • 26
    Sep 26th
    26 Files
  • 27
    Sep 27th
    39 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close