what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 223 RSS Feed

Files

Packet Storm New Exploits For March, 2015
Posted Apr 1, 2015
Authored by Todd J. | Site packetstormsecurity.com

This archive contains 224 exploits that were added to Packet Storm in March, 2015.

tags | exploit
systems | linux
SHA-256 | ff2d4f6a5e0d36e7a400694be6896782332b861bb542ff96067e295fc65f2246
Adobe Flash Player ByteArray With Workers Use After Free
Posted Mar 30, 2015
Authored by juan vazquez, temp66, hdarwin | Site metasploit.com

This Metasploit module exploits an use after free vulnerability in Adobe Flash Player. The vulnerability occurs when the ByteArray assigned to the current ApplicationDomain is freed from an ActionScript worker, who can fill the memory and notify the main thread to corrupt the new contents. This Metasploit module has been tested successfully on Windows 7 SP1 (32 bits), IE 8 to IE 11 and Flash 16.0.0.296.

tags | exploit
systems | windows
advisories | CVE-2015-0313
SHA-256 | bb349a822c1cc70d4d8f5f21a7eac4a134384b42aa63d3ce02ebae6b666c8b6a
Windows Run Command As User
Posted Mar 30, 2015
Authored by Ben Campbell, Kx499 | Site metasploit.com

This Metasploit module will login with the specified username/password and execute the supplied command as a hidden process. Output is not returned by default. Unless targetting a local user either set the DOMAIN, or specify a UPN user format (e.g. user@domain). This uses the CreateProcessWithLogonW WinAPI function. A custom command line can be sent instead of uploading an executable. APPLICAITON_NAME and COMMAND_LINE are passed to lpApplicationName and lpCommandLine respectively. See the MSDN documentation for how these two values interact.

tags | exploit, local
SHA-256 | 9708939c73c492103ede2da0dee3008422e7c17f9e1ed2961f1a52f94e096c31
JBoss JMXInvokerServlet Remote Command Execution
Posted Mar 30, 2015
Authored by Luca Carettoni

This code exploits a common misconfiguration in JBoss Application Server. Whenever the JMX Invoker is exposed with the default configuration, a malicious "MarshalledInvocation" serialized Java object allows to execute arbitrary code. This exploit works even if the "Web-Console" and the "JMX Console" are protected or disabled.

tags | exploit, java, web, arbitrary
SHA-256 | 2f89a911033600e43c401de947c053ee9c90b4063ccb92f8ff41a305ec2aa1aa
Palo Alto Traps Server 3.1.2.1546 Cross Site Scripting
Posted Mar 30, 2015
Authored by Michael Hendrickx

Palo Alto Traps Server (formerly Cyvera Endpoint Protection) version 3.1.2.1546 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2015-2223
SHA-256 | 2a5453f88566d77d7e19e2aff808085c16343d88f9a63b35afd70af9ca9d1ff8
Fedora 12 setroubleshootd Local Root Proof Of Concept
Posted Mar 30, 2015
Authored by Sebastian Krahmer

Fedora 21 setroubleshootd local root proof of concept exploit.

tags | exploit, local, root, proof of concept
systems | linux, fedora
SHA-256 | 11547b584c917b7adec234f03ba707e23f8dbd3a90635d158af5ff31b4a7e6b8
FiyoCMS 2.0.1.8 XSS / SQL Injection / URL Bypass
Posted Mar 30, 2015
Authored by Mahendra

FiyoCMS version 2.0.1.8 suffers from url bypass, cross site scripting, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, bypass
advisories | CVE-2014-9145, CVE-2014-9146, CVE-2014-9147, CVE-2014-9148
SHA-256 | 470d9cc24c0c32460aaed00b5873729ab9615222c8ae2e650bff9aa3cc74a162
Joomla Gallery WD SQL Injection
Posted Mar 30, 2015
Authored by CrashBandicot

Joomla Gallery WD component suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | b474d36529f730c41b9a954fc193ce5a1b3d73db25832f3ec198d4787eed5909
Joomla Contact Form Maker 1.0.1 SQL Injection
Posted Mar 29, 2015
Authored by TUNISIAN CYBER

Joomla Contact Form Maker component version 1.0.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c72c33feb4b25c9235eb9d9cbf2368498704c1d5d0f542f88ca3d988ddf92a7c
WebDepo CMS SQL Injection
Posted Mar 29, 2015
Authored by Cleiton Pinheiro

WebDepo CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f56f63f5febb8cdd466c97568d2d801a1f2724b2c57e61fbaf91feeeb476dc43
ProjectPier 0.8.8 SP2 Cross Site Scripting
Posted Mar 29, 2015
Authored by Jaydeep Dave

ProjectPier version 0.8.8 SP2 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 8405f0debc4bd59bdf121d4d4769a460a5529cb51ef81d22175d4907a68b8d03
HTTrack Website Copier 3.48-21 DLL Hijacking
Posted Mar 29, 2015
Authored by TUNISIAN CYBER

HTTrack Website Copier version 3.48-21 suffers from a dll hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | 5b24d7f3119441e77c5e3e6a20e6015752be4c78cb1e43d2901fe525ffef2574
WordPress Aspose Importer / Exporter 1.0 File Download
Posted Mar 29, 2015
Authored by Ashiyane Digital Security Team

WordPress Aspose Importer and Exporter plugin version 1.0 suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | 8be70304bc73a2fce09d3c01c02b74c8a0d4d802ca303d85456977cb45bd45c8
BZR Player 1.03 DLL Hijacking
Posted Mar 29, 2015
Authored by TUNISIAN CYBER

BZR Player version 1.03 suffers from a dll hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | 0fbb6fd6fe0814d46a51fcecaf7188da9a584d6adcd094845e90931c419be24a
UltraISO 9.6.2.3059 DLL Hijacking
Posted Mar 29, 2015
Authored by TUNISIAN CYBER

UltraISO version 9.6.2.3059 suffers from a dll hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | 76c71a688dbad49346ec895688927f92c9f86a3655403d3252cbd68166306a0c
WordPress Aspose PDF Exporter File Download
Posted Mar 29, 2015
Authored by Ashiyane Digital Security Team

WordPress Aspose PDF Exporter plugin suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | 1ffd4f7657e572760a2a7a2208b972d910c2e268df6c4f7fc9817750e8daf078
WordPress Aspose Doc Exporter File Download
Posted Mar 29, 2015
Authored by Ashiyane Digital Security Team, ACC3SS

WordPress Aspose Doc Exporter plugin suffers from an arbitrary file download vulnerability.

tags | exploit, arbitrary, info disclosure
SHA-256 | 84dfbe2929095980e143d513dd3bd79f51a639dcb3c65727c539b46a251b7be7
ZIP Password Recovery Professional 7.1 DLL Hijacking
Posted Mar 29, 2015
Authored by TUNISIAN CYBER

ZIP Password Recovery Professional version 7.1 suffers from a dll hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | 4aab9cb58a11f4c6355cf00d3b1ed0d38077aa67527637ae66e038677d2c47c9
GoAhead 3.4.1 Heap Overflow / Traversal
Posted Mar 28, 2015
Authored by Matthew Daley

GoAhead web server versions 3.0.0 through 3.4.1 suffers from heap overflow and directory traversal vulnerabilities.

tags | exploit, web, overflow, vulnerability, file inclusion
advisories | CVE-2014-9707
SHA-256 | 6fb18dfd80ce463f675f713e9ebec9b8c5a991abc545cf1b1fbf82cc2f64697b
Appweb Web Server Denial Of Service
Posted Mar 28, 2015
Authored by Matthew Daley

Appweb Web Server suffers from a denial of service vulnerability.

tags | exploit, web, denial of service
advisories | CVE-2014-9708
SHA-256 | e59a4ebe08e7c3f7777a2c603a71d5db8d059f0c0ece77091aadd4aa5da52401
WordPress Google Map Travel 3.4 XSS / CSRF
Posted Mar 28, 2015
Authored by Kaustubh G. Padwad

WordPress AB Google Map Travel (AB-MAP) plugin version 4.0 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2015-2755
SHA-256 | dbd0939d53280d5f0c1443437fc3c64a3c5ad487379041dd2756ab5536b86ce4
Manage Engine Desktop Central 9 Unauthorized Administrative Password Reset
Posted Mar 27, 2015

A remote unauthenticated user can change the password of any Manage Engine Desktop Central user with the Administrator role (DCAdmin).

tags | exploit, remote
advisories | CVE-2015-2560
SHA-256 | 4e564bd659684313462675a23bdcdb7cff6e5368a61d78b38a3ee71428ffb7f0
WebGate WinRDS 2.0.8 StopSiteAllChannel Stack Overflow
Posted Mar 27, 2015
Authored by Praveen Darshanam

WebGate WinRDS version 2.0.8 suffers from a StopSiteAllChannel stack overflow vulnerability.

tags | exploit, overflow
advisories | CVE-2015-2094
SHA-256 | 7484b0bcf3d1e469356ad299ee2cba7f18f007b4e21729c676d7230e1f1e2a47
Internet Download Manager 6.20 Local Buffer Overflow
Posted Mar 27, 2015
Authored by TUNISIAN CYBER

Internet Download Manager version 6.20 suffers from a local buffer overflow vulnerability.

tags | exploit, overflow, local
SHA-256 | ea86e49c3a444a60d3b5c98219843360bca802d317a568dcc2c43328eeaa2b0f
AfterLogic WebMail Lite Authentication Bypass
Posted Mar 27, 2015
Authored by Paulos Yibelo

AfterLogic WebMail Lite allows for an unauthenticated user to set an administrative password.

tags | exploit, bypass
SHA-256 | bf60678dc4156a2c4163e6ba2c9b3dc300a0635313915e2001465b0a83a9262a
Page 1 of 9
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close