exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 171 RSS Feed

Files

Packet Storm New Exploits For March, 2022
Posted Apr 1, 2022
Authored by Todd J. | Site packetstormsecurity.com

This archive contains all of the 170 exploits added to Packet Storm in March, 2022.

tags | exploit
SHA-256 | 6bfa5ea340ba93d1eab5494d494509bb601607d56b218558b80524425948251e
Spring Cloud Function SpEL Injection
Posted Mar 31, 2022
Authored by Spencer McIntyre, m09u3r, hktalent | Site metasploit.com

Spring Cloud Function versions prior to 3.1.7 and 3.2.3 are vulnerable to remote code execution due to using an unsafe evaluation context with user-provided queries. By crafting a request to the application and setting the spring.cloud.function.routing-expression header, an unauthenticated attacker can gain remote code execution. Both patched and unpatched servers will respond with a 500 server error and a JSON encoded message.

tags | exploit, remote, code execution
advisories | CVE-2022-22963
SHA-256 | 191fd2ef6dcf8a98bc701657de72fbfe2250e9ec9091b7372a38ea1abcff6241
IdeaRE RefTree Path Traversal
Posted Mar 31, 2022
Authored by Savino Sisco

IdeaRE RefTree versions prior to 2021.09.17 suffer from a path traversal vulnerability.

tags | exploit
advisories | CVE-2022-27248
SHA-256 | 6c01288d24fb06203fba1bbb4a1569c7c1519c40ba0e613d0c951377f72407e7
IdeaRE RefTree Shell Upload
Posted Mar 31, 2022
Authored by Savino Sisco

IdeaRE RefTree versions prior to 2021.09.17 suffer from a remote shell upload vulnerability.

tags | exploit, remote, shell
advisories | CVE-2022-27249
SHA-256 | 7a1f36a186daaabfb1cb5a35f53c2411f1ac4fc02655a8038cdac234c32dd9fd
Chrome DeserializeFromMessage Validation Issue
Posted Mar 31, 2022
Authored by Google Security Research, Glazvunov

Chrome has an issue where a malformed message sent to DeserializeFromMessage may trigger deserialization of out-of-bounds data.

tags | exploit
advisories | CVE-2022-0797
SHA-256 | f016c2cc33607e475f4fb0feaf3b97c31f557eea1cb21d5c1b76fc4fa4ad9003
EG Free AntiVirus 2020 Privilege Escalation / Unquoted Service Path
Posted Mar 31, 2022
Authored by Shahrukh Iqbal Mirza

EG Free AntiVirus version 2020 suffers from an unquoted service path vulnerability that can lead to privilege escalation.

tags | exploit
advisories | CVE-2021-46439
SHA-256 | f5afeadbe9a6dd42729251f44605027c495f8ca53f5077f1ef0566b30d207ffd
Spoofer 1.4.6 Privilege Escalation / Unquoted Service Path
Posted Mar 31, 2022
Authored by Asim Sattar

Spoofer version 1.4.6 suffers from an unquoted service path vulnerability that can lead to privilege escalation.

tags | exploit
advisories | CVE-2021-46443
SHA-256 | 6e36f8ead3bb9754bebd29f1138b16de9f85c211a2321e246d8956e9be5fe982
Medical Hub Directory Site 1.0 SQL Injection
Posted Mar 31, 2022
Authored by Hejap Zairy

Medical Hub Directory Site version 1.0 suffers from a remote blind SQL injection vulnerability. This research was submitted on the same day Packet Storm received similar findings from Saud Alenazi.

tags | exploit, remote, sql injection
SHA-256 | 485f05f134b2d3819d19208535bf09e2d66a1a262580141bc9a9964b00e68204
Message System 1.0 SQL Injection
Posted Mar 31, 2022
Authored by Hejap Zairy

Message System version 1.0 suffers from a remote SQL injection vulnerability that can lead to remote code execution.

tags | exploit, remote, code execution, sql injection
SHA-256 | f726216137cb25cc61ebd0212e3d991811ebe3e9be1b4d7c85db6f64b5cdf1be
Message System 1.0 Cross Site Scripting
Posted Mar 31, 2022
Authored by Hejap Zairy

Message System version 1.0 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 4f43e6605407609b1bcdd1c5a3be22479cef1d68b174b04b20a647976713db71
Chrome safe_browsing::ThreatDetails::OnReceivedThreatDOMDetails Use-After-Free
Posted Mar 30, 2022
Authored by Google Security Research, Glazvunov

Chrome suffers from a heap use-after-free vulnerability in safe_browsing::ThreatDetails::OnReceivedThreatDOMDetails. Versions affected include Google Chrome 96.0.4664.110 (Official Build) (64-bit) and Chromium 99.0.4807.0 (Developer Build) (64-bit).

tags | exploit
advisories | CVE-2022-0289
SHA-256 | abc96b3ccb6e22768b4210d82c4a8f2e4acb93ed93b406ea11be905b7b11fd03
Joomla! 4.1.0 Zip Slip File Overwrite / Path Traversal
Posted Mar 30, 2022
Authored by EgiX | Site karmainsecurity.com

Joomla! versions 4.1.0 and below suffer from path traversal and file overwrite vulnerabilities due to misplaced trust in the handling of compressed archives.

tags | exploit, vulnerability
advisories | CVE-2022-23793
SHA-256 | 3659bb2a193b54ec58750cfb109d9f00cfd739f7828d6a6d4fdff0e0ff2be911
WordPress Easy Cookie Policy 1.6.2 Cross Site Scripting
Posted Mar 30, 2022
Authored by 0xB9

WordPress Easy Cookie Policy plugin version 1.6.2 suffers from persistent cross site scripting vulnerability due to a broken access control.

tags | exploit, xss
advisories | CVE-2021-24405
SHA-256 | 0f40c07bb7f4bcf7b5bf25dff22799cb9ddc37674fc191e7558caaaf8e60a2df
WordPress CleanTalk 5.173 Cross Site Scripting
Posted Mar 30, 2022
Authored by Ramuel Gall | Site wordfence.com

WordPress CleanTalk plugin versions 5.173 and below suffer from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2022-28221, CVE-2022-28222
SHA-256 | 4136278cd0e53a4bc876e08a79e68f309bd0ea7712eb64d14cfca18b9f7d6147
Kramer VIAware 2.5.0719.1034 Remote Code Execution
Posted Mar 30, 2022
Authored by BallO, sharkmoos

Kramer VIAware version 2.5.0719.1034 suffers from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2019-17124
SHA-256 | 71fd9ed67f1c3636b46e0f35d6d135b218a93103bbc2f9e74dd9d79b2c4d145c
PostgreSQL 11.7 Remote Code Execution
Posted Mar 30, 2022
Authored by b4keSn4ke

PostgreSQL versions 9.3 through 11.7 remote code execution exploit.

tags | exploit, remote, code execution
advisories | CVE-2019-9193
SHA-256 | e597a53141013a6e5aaeefcbb4e28ade73077b7f1f7b8c7994ae9d9031e1d2ff
Medical Hub Directory Site 1.0 SQL Injection
Posted Mar 30, 2022
Authored by Saud Alenazi

Medical Hub Directory Site version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | ee8c310121323386739682f3a0a47f7c5876d9f946a2888843f501157e2fb296
Medical Hub Directory Site 1.0 Shell Upload
Posted Mar 30, 2022
Authored by Hejap Zairy

Medical Hub Directory Site version 1.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 200e45a8e60bd48fae8a91e1a1286756e616a4d42f06d24c5eb5531ecfa01d70
Medical Hub Directory Site 1.0 Cross Site Scripting
Posted Mar 30, 2022
Authored by Hejap Zairy

Medical Hub Directory Site version 1.0 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 6dbf01850ff08bd1a2757bdd19e72d23b225be15ae7664524a980f5ce48138e4
Medical Hub Directory Site 1.0 Local File Inclusion
Posted Mar 30, 2022
Authored by Hejap Zairy

Medical Hub Directory Site version 1.0 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | cd4822cdfbe0799d9da4d14ad9b06e2c18c4f3f1ea3b9ffdc72ec61ba4ca5ad0
CSZ CMS 1.2.9 SQL Injection
Posted Mar 30, 2022
Authored by Rahad Chowdhury

CSZ CMS version 1.2.9 suffers from multiple remote blind SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
advisories | CVE-2021-43701
SHA-256 | 7431b5b000bf66ac213ad90301229b8ea2b82227a6d242c3733700f2c7f0470d
WordPress Video-Synchro-PDF 1.7.4 Local File Inclusion
Posted Mar 30, 2022
Authored by Hassan Khan Yusufzai

WordPress Video-Synchro-PDF plugin version 1.7.4 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | f94520cb3421369e072051761bcdb9d992081457e9af1fbf068b1e7431481880
WordPress Cab-Fare-Calculator 1.0.3 Local File Inclusion
Posted Mar 30, 2022
Authored by Hassan Khan Yusufzai

WordPress Cab-Fare-Calculator plugin version 1.0.3 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 86ee0c35b5409a672125451f0cd0f8722c0e3f49332d9a986e3674880b8c4093
Atom CMS 1.0.2 Shell Upload
Posted Mar 30, 2022
Authored by Ashish Koli

Atom CMS version 1.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
advisories | CVE-2022-25487
SHA-256 | a1ff9987b6bdc85d32bdf744311ddc50def1d3ba515fb3bb6f39d1a90ab9b9ff
WordPress Donorbox-Donation-Form 7.1.6 Cross Site Scripting
Posted Mar 30, 2022
Authored by Hassan Khan Yusufzai

WordPress Donorbox-Donation-Form plugin version 7.1.6 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2fc87137716fc7ebe54874b9d582f16eba4586f4c195a3b359f3691bcccefa04
Page 1 of 7
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close