what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 168 RSS Feed

Files

Sellacious eCommerce Shop Cross Site Scripting
Posted May 13, 2020
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Sellacious eCommerce Shop suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 196ab4b61f5e94a2f03aa875f07eba9b1953c199d6022d1281f851d7e3335a34
Tryton 5.4 Cross Site Scripting
Posted May 13, 2020
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Tryton version 5.4 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 4c96fa3580b6561a60b15f2a32d8b9788f1fa4ce3f568b13baef2a4e31f1a2c9
Remote Desktop Audit 2.3.0.157 Buffer Overflow
Posted May 13, 2020
Authored by gurbanli

Remote Desktop Audit version 2.3.0.157 suffers from a buffer overflow vulnerability.

tags | exploit, remote, overflow
SHA-256 | a873dd3a0f2c89613633590531ec9153a6c1897d765684d348e6738c5e833244
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
Posted May 12, 2020
Authored by Brendan Coles, Chris Lyne | Site metasploit.com

Druva inSync client for Windows exposes a network service on TCP port 6064 on the local network interface. inSync versions 6.5.2 and prior do not validate user-supplied program paths in RPC type 5 messages, allowing execution of arbitrary commands as SYSTEM. This Metasploit module has been tested successfully on inSync version 6.5.2r99097 on Windows 7 SP1 (x64).

tags | exploit, arbitrary, local, tcp
systems | windows
advisories | CVE-2019-3999
SHA-256 | 12e3b974b7cb427087439bf5f922afb373bca8c3346525b183f6422b28801319
Netsweeper WebAdmin unixlogin.php Python Code Injection
Posted May 12, 2020
Authored by wvu | Site metasploit.com

This Metasploit module exploits a Python code injection in the Netsweeper WebAdmin component's unixlogin.php script, for versions 6.4.4 and prior, to execute code as the root user. Authentication is bypassed by sending a random whitelisted Referer header in each request. Tested on the CentOS Linux-based Netsweeper 6.4.3 and 6.4.4 ISOs. Though the advisory lists 6.4.3 and prior as vulnerable, 6.4.4 has been confirmed exploitable.

tags | exploit, root, php, python
systems | linux, centos
SHA-256 | dcae513897070a9218f0bedaca27c407e24184902dfdcf5421907f51081acf14
SaltStack Salt Master/Minion Unauthenticated Remote Code Execution
Posted May 12, 2020
Authored by wvu, F-Secure | Site metasploit.com

This Metasploit module exploits unauthenticated access to the runner() and _send_pub() methods in the SaltStack Salt master's ZeroMQ request server, for versions 2019.2.3 and earlier and 3000.1 and earlier, to execute code as root on either the master or on select minions. VMware vRealize Operations Manager versions 7.5.0 through 8.1.0 are known to be affected by the Salt vulnerabilities. Tested against SaltStack Salt 2019.2.3 and 3000.1 on Ubuntu 18.04, as well as Vulhub's Docker image.

tags | exploit, root, vulnerability
systems | linux, ubuntu
advisories | CVE-2020-11651, CVE-2020-11652
SHA-256 | 8a5e7d31040e1c21ab99f881d936f3d17aadab8f8786980255feab1b1b628534
Adobe DNG SDK Memory Corruption
Posted May 12, 2020
Authored by Google Security Research, mjurczyk

Adobe DNG SDK suffers from memory corruption and other crashes caused by malformed .dng images.

tags | exploit
SHA-256 | 5e0cb4cf3dda82ee681cc340b6ee9c3fd167c5e730a49ac40effd6914c779db6
Adobe DNG SDK dng_lossless_decoder::DecodeImage Out-Of-Bounds Read
Posted May 12, 2020
Authored by Google Security Research, mjurczyk

Adobe DNG SDK suffers from an out-of-bounds read that can lead to an arbitrary write vulnerability in dng_lossless_decoder::DecodeImage.

tags | exploit, arbitrary
SHA-256 | 10f9d909a875c4ab314d16a0b9077d0dc02afff41825b02a198cf4fd6e780afd
LanSend 3.2 Buffer Overflow
Posted May 12, 2020
Authored by gurbanli

LanSend version 3.2 suffers from a buffer overflow vulnerability.

tags | exploit, overflow
SHA-256 | aea9ad2b46bc92ead403dc4a49108f5c7b285ef6a058e44d905615a2e913ba0f
qdPM 9.1 Arbitrary File Upload
Posted May 12, 2020
Authored by Besim Altinok, Ismail Bozkurt

qdPM version 9.1 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 29677c9aeba89af9fcf295f75937caccf52029e7fa9463e55173aedd624ed875
Cisco Digital Network Architecture Center 1.3.1.4 Cross Site Scripting
Posted May 12, 2020
Authored by Dylan Garnaud, Benoit Malaboeuf

Cisco Digital Network Architecture Center version 1.3.1.4 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
systems | cisco
advisories | CVE-2019-15253
SHA-256 | b79e78cd34f779177fdeb2527036085286faae53fc72ed9b3b21853e608b7b38
CuteNews 2.1.2 Authenticated Shell Upload
Posted May 12, 2020
Authored by Vigov5

CuteNews version 2.1.2 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell, file upload
SHA-256 | 1bf71f9d33300d7dc2cc4132c6b15db181f3b4df8f6712432611c28b8929c56a
macOS 320.whatis Script Privilege Escalation
Posted May 12, 2020
Authored by Csaba Fitzl

macOS 320.whatis Script suffers from a privilege escalation vulnerability.

tags | exploit
SHA-256 | e578f65b68fcf2548e910793e37c196e060d6250ff94cec53221209d10a3ca20
TylerTech Eagle 2018.3.11 Remote Code Execution
Posted May 12, 2020
Authored by Anthony Cole

TylerTech Eagle version 2018.3.11 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
SHA-256 | 966770ccb06e6f9e5ff875bbd6fc8578e03727384a0fee39d60912d09e63779b
WordPress ChopSlider3 3.4 SQL Injection
Posted May 12, 2020
Authored by SunCSR

WordPress ChopSlider3 plugin version 3.4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2020-11530
SHA-256 | cfc7ba3799b36c678dc3edc35d0a5f83e09a6b543c87ba67384476ee4398aafa
Orchard Core RC1 Cross Site Scripting
Posted May 12, 2020
Authored by SunCSR

Orchard Core version RC1 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 72a8a68f1801a2b8f14ac871496aa71b35ce4dcde4dcdf45516856143cc7c333
Chrome Typer::Visitor::TypeInductionVariablePhi Type Inference
Posted May 12, 2020
Authored by Google Security Research, Glazvunov, Tim Willis

Chrome suffers from a Typer::Visitor::TypeInductionVariablePhi type inference issue.

tags | exploit
SHA-256 | 97541b515f1146557567913a8db64be5813d2b15b948ea1105c9e3337c28233a
LibreNMS 1.46 SQL Injection
Posted May 11, 2020
Authored by Punt

LibreNMS version 1.46 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 1925a6d2f57f543b740400ab21ad9ed57e19ccefe92a7f9e83906f831716b8b6
Complaint Management System 1.0 SQL Injection
Posted May 11, 2020
Authored by BKpatron

Complaint Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | 35d2440e75b29d83a0dc93efd0b52bb8c57d111f48e476305cfc5e54be780362
CuteNews 2.1.2 Arbitrary File Deletion
Posted May 11, 2020
Authored by Besim Altinok, Ismail Bozkurt

CuteNews version 2.1.2 suffers from an arbitrary file deletion vulnerability.

tags | exploit, arbitrary
SHA-256 | 37c5678fdbbbfaf9881b385d209475aaecc9505027b0b083c1f4c986bfdb3f5c
Victor CMS 1.0 SQL Injection
Posted May 11, 2020
Authored by BKpatron

Victor CMS version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | e097b919f522cb4207e78c3be4ec2486e33cb823cd9a4dc313b72d15f034f71d
Online AgroCulture Farm Management System 1.0 SQL Injection
Posted May 11, 2020
Authored by Tarun Sehgal

Online AgroCulture Farm Management System version 1.0 suffers from a remote SQL injection vulnerability that leverages the uname parameter.

tags | exploit, remote, sql injection
SHA-256 | 0b7382ff7d0d2dda843490019b9f07be87c98f317b10819dc149aaff71db39f2
Pi-hole 4.4 Remote Code Execution / Privilege Escalation
Posted May 10, 2020
Authored by Nick Frichette

Pi-hole versions 4.4 and below remote code execution and privilege escalation exploit.

tags | exploit, remote, code execution
advisories | CVE-2020-11108
SHA-256 | 24dbec0272280c917c4f6f1294f5d251879231087642729ccdd7a1b727a27cff
Pi-hole 4.4 Remote Code Execution
Posted May 10, 2020
Authored by Nick Frichette

Pi-hole versions 4.4 and below suffer from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2020-11108
SHA-256 | c400406dcb79630cf4da18e7a41e5e507d3715a4c57d6150947c2924a9d53b97
Kartris 1.6 Arbitrary File Upload
Posted May 9, 2020
Authored by Nhat Ha

Kartris version 1.6 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 1893df3860645717ed77b36829cd27018d61135d550260a8e7b0722461344c66
Page 4 of 7
Back23456Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Information Of Hundreds Of European Politicians Found On Dark Web
Posted May 31, 2024

tags | headline, hacker, government, privacy
Okta Says Customer Identity Cloud Prone To Credential Stuffing Attacks
Posted May 31, 2024

tags | headline, password
Law Enforcement Operation Takes Aim At An Often Overlooked Cybercrime Lynchpin
Posted May 31, 2024

tags | headline, hacker, government, malware, cybercrime, fraud
Trump Guilty On All 34 Felony Counts
Posted May 30, 2024

tags | headline, government, usa, fraud
Australia Looking Into Alleged Ticketmaster Hack
Posted May 30, 2024

tags | headline, hacker, privacy, australia, data loss, fbi
Critics Of Putin And His Allies Targeted With Spyware Inside The EU
Posted May 30, 2024

tags | headline, government, phone, russia, cyberwar, israel, spyware
Massive 911 S5 Botnet Dismantled, Mastermind Arrested
Posted May 30, 2024

tags | headline, hacker, government, china, botnet
FBCS Data Breach Impact Grows To 3.2 Million Individuals
Posted May 30, 2024

tags | headline, hacker, privacy, data loss
Researchers Crack 11-Year-Old Password, Recover $3 Million In Bitcoin
Posted May 30, 2024

tags | headline, hacker, password, cryptography
BreachForums Returns Just Weeks After FBI-Led Takedown
Posted May 29, 2024

tags | headline, hacker, government, privacy, usa, data loss, password, fbi
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close