exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 397 RSS Feed

Files Date: 2018-11-01 to 2018-11-30

Moxa NPort W2x50A 2.1 OS Command Injection
Posted Nov 29, 2018
Authored by Maxim Khazov

Moxa NPort W2x50A products with firmware version 2.1 Build_17112017 or lower are vulnerable to several authenticated OS command injection vulnerabilities.

tags | exploit, vulnerability
advisories | CVE-2017-12120, CVE-2018-19660
SHA-256 | 0f86dde8e1c44108d2214acb30772974903fb5e2efa4f23d272a62cd0ca53b09
knc (Kerberized NetCat) Denial Of Service
Posted Nov 29, 2018
Authored by Imre Rad

knc (Kerberised NetCat) versions before 1.11-1 are vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another service running on the targeted host. Proof of concept included.

tags | exploit, denial of service, proof of concept
advisories | CVE-2017-9732
SHA-256 | 5f21249af2b570413ccedbc2d38d69f7569143fd0ffd8e6431e4db2f29a7fb53
WordPress Events Calendar Premium 1.0 Database Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress Events Calendar Premium plugin version 1.0 suffers from a database disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 383704f897617826c4fdc3af390d64e0b37907bf08dcf05be37a493b309db2f8
WordPress WP Complete Backup 3.0.5 Database Backup Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress WP Complete Backup plugin version 3.0.5 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 92c09b8545a80266ce8ccfa5cf484366783c4ebfe56b74dc62f2ba6e956cb5ec
WordPress Jazzy Forms 1.1.1 Database Backup Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress Jazzy Forms plugin version 1.1.1 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 9403666c8c643458d61b39b4df10497e4a2119781f40ecb04bbf328215296db3
WordPress pm_market 1.0 Database Backup Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress pm_market plugin version 1.0 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 49057b9856f52e7c1326bb6a40eec2adce2781ea4cc9af44a1dd3056fcc88fb0
WordPress wawp_framework 1.0 Database Backup Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress wawp_framework plugin version 1.0 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 8fbdbecfa3686c56da6732ca409952493ea81d7d040d9afd264b3e20d92f888b
Wireshark Analyzer 2.6.5
Posted Nov 29, 2018
Authored by Gerald Combs | Site wireshark.org

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers.

Changes: The Windows installers now ship with Qt 5.9.7. Previously they shipped with Qt 5.9.5. Multiple vulnerabilities addressed.
tags | tool, sniffer, protocol
systems | windows, unix
advisories | CVE-2018-19622, CVE-2018-19623, CVE-2018-19624, CVE-2018-19625, CVE-2018-19626, CVE-2018-19627, CVE-2018-19628
SHA-256 | 93155b798544b2f07693920f4ac1b531c952965ee4eb1d98419961240177438a
Gentoo Linux Security Advisory 201811-21
Posted Nov 29, 2018
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201811-21 - Multiple vulnerabilities have been found in OpenSSL, the worst of which may lead to a Denial of Service condition. Versions less than 1.0.2o are affected.

tags | advisory, denial of service, vulnerability
systems | linux, gentoo
advisories | CVE-2018-0733, CVE-2018-0737, CVE-2018-0739
SHA-256 | c1d2c4c1f169d7444a8ec783ed15c7533f43aef45a89c4f6cbccef76230c09e9
Gentoo Linux Security Advisory 201811-22
Posted Nov 29, 2018
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201811-22 - Multiple vulnerabilities have been found in RPM, the worst of which could allow a remote attacker to escalate privileges. Versions less than 4.14.1 are affected.

tags | advisory, remote, vulnerability
systems | linux, gentoo
advisories | CVE-2013-6435, CVE-2014-8118, CVE-2017-7501
SHA-256 | dbe5366b678db36b941163032978eb4793921ab8f835a04b9d9232bde15f35a3
WordPress Delme 3.0 Database Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress Delme plugin version 3.0 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | cdf0038016909bdc9fbbb6b0131d33c91251f0f21c5d2c20ada0f2c1d6a2a0d1
WordPress user-spam-remover 1.0 Database Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress user-spam-remover plugin version 1.0 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 545976aab87512242d5f58cedab4af05cef9bd274b86805b2ce96fac81605ad9
WordPress hwm_board 1.0 Arbitrary File Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress hwm_board plugin version 1.0 suffers from an arbitrary database download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | 92b1425f6c23ab281b94eb21d5263e062608fbbdc2a35ca2c23fdcc9108ea18c
WordPress uploadingdownloading-non-latin-filename 1.1.5 Arbitrary File Download
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress uploadingdownloading-non-latin-filename plugin version 1.1.5 suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | 53d7a94a9e18f3b4caddffdf4610c695553544082472c38337520f6df805ee5e
WordPress sermon-shortcodes 1.0 Arbitrary File Download
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress sermon-shortcodes plugin version 1.0 suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | 219e65b364ab6c17799bc19d5963a1260774c9cf1f4e1d23c741dfdb9ef8ff14
WordPress allow-l10n-upload-filename 1.0 Arbitrary File Download
Posted Nov 29, 2018
Authored by KingSkrupellos

WordPress allow-l10n-upload-filename plugin version 1.0 suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | ec3365bc1a665d76c716098268b6ade37ed13bab4bfe312cbba37e0708d626fd
Joomla Event Booking 3.8.3 Database Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

Joomla Event Booking component version 3.8.3 suffers from a database backup disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 9acbedfbb61ff2ca14e2453561fdf51bad8d74534c4e7896822e5b073624529d
Joomla DJ Image Slider 3.2.3 Database Disclosure
Posted Nov 29, 2018
Authored by KingSkrupellos

Joomla DJ Image Slider component version 3.2.3 suffers from a database disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 73183e225d7b9669b460d103ab9a3882cac5bf20a75484bbdc8c64af23c4f484
CORS Attacks
Posted Nov 29, 2018
Authored by Milad Khoshdel

This whitepaper focuses on attacks related to CORS, or Cross-Origin Resource Sharing.

tags | paper
SHA-256 | 3a51921a22b49222f2339d96c3e7837e52892458d3faf88b15a8ebdbd8876cb4
Joomla Fabrik 3.9 CSRF / LFI / Shell Upload
Posted Nov 29, 2018
Authored by KingSkrupellos

Joomla Fabrik component version 3.9 suffers from cross site request forgery, local file inclusion, and remote shell upload vulnerabilities.

tags | exploit, remote, shell, local, vulnerability, file inclusion, csrf
SHA-256 | 1913b5395f0c68ac87d24dbcb440be3c830667b96bebeb7c0a20df74aa059240
Unitrends Enterprise Backup bpserverd Privilege Escalation
Posted Nov 28, 2018
Authored by h00die, Benny Husted, Cale Smith, Jared Arave | Site metasploit.com

It was discovered that the Unitrends bpserverd proprietary protocol, as exposed via xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target system. This is very similar to exploits/linux/misc/ueb9_bpserverd however it runs against the localhost by dropping a python script on the local file system. Unitrends stopped bpserverd from listening remotely on version 10.

tags | exploit, remote, arbitrary, local, root, protocol, python
systems | linux
advisories | CVE-2018-6329
SHA-256 | 78074b1701e40ea4ef9e046d50ffaa646aa27cf4177d6b17c6371f5f32a674b7
Ubuntu Security Notice USN-3830-1
Posted Nov 28, 2018
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3830-1 - USN-3804-1 fixed vulnerabilities in OpenJDK. Unfortunately, that update introduced a regression when validating JAR files that prevented Java applications from finding classes in some situations. This update fixes the problem.

tags | advisory, java, vulnerability
systems | linux, ubuntu
SHA-256 | 166b04353de713beab9d08eea9a06f119e07b1b80978dd2605262a24dc29f7b6
Debian Security Advisory 4346-1
Posted Nov 28, 2018
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4346-1 - Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

tags | advisory, denial of service, arbitrary, vulnerability
systems | linux, debian
advisories | CVE-2018-19409, CVE-2018-19475, CVE-2018-19476, CVE-2018-19477
SHA-256 | 31d5f9ccd80e2ae52f634417dc51d4efec799681af5b520ee3732b3908bb345d
FreeBSD Security Advisory - FreeBSD-SA-18:13.nfs
Posted Nov 28, 2018
Authored by Jakub Jirasek | Site security.freebsd.org

FreeBSD Security Advisory - Insufficient and improper checking in the NFS server code could cause a denial of service or possibly remote code execution via a specially crafted network packet. A remote attacker could cause the NFS server to crash, resulting in a denial of service, or possibly execute arbitrary code on the server.

tags | advisory, remote, denial of service, arbitrary, code execution
systems | freebsd, bsd
advisories | CVE-2018-17157, CVE-2018-17158, CVE-2018-17159
SHA-256 | 10bcc1748ee3a9d625fa8d7384fa8357ec3df2199059cc67ec2a7fe57ef95a19
Htcap Analysis Tool 1.1.0
Posted Nov 28, 2018
Authored by Filippo Cavallarin

Htcap is a web application analysis tool for detecting communications between javascript and the server. It crawls the target application and maps ajax calls, dynamically inserted scripts, websockets calls, dynamically loaded resources and some interesting elements. The generated report is meant to be a good starting point for a manual web application security audit. Htcap is written in python and uses phantomjs to load pages injecting a probe that analyzes javascript behaviour. Once injected, the probe, overrides native javascript methods in order to intercept communications and DOM changes. It also simulates user interaction by firing all attached events and by filling html inputs.

Changes: In this release phantomjs has been replaced by headless chrome (nodejs + puppetter) and the crawl engine has been partially rewritten to take advantage of async/await features available in chrome.
tags | tool, web, javascript, sniffer, python
SHA-256 | dd46625edf20ec566996b733efec4fa6ab1a394f429074cafd338ed82f2fc1bc
Page 1 of 16
Back12345Next

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    53 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close