exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 21 of 21 RSS Feed

Files from IHTeam

First Active2006-08-17
Last Active2023-06-12
TerraMaster TOS 4.2.06 Remote Code Execution
Posted Jun 12, 2023
Authored by IHTeam, h00die-gr3y | Site metasploit.com

This Metasploit module exploits an unauthenticated remote code execution vulnerability in TerraMaster TOS versions 4.2.06 and below via shell metacharacters in the Event parameter at vulnerable endpoint include/makecvs.php during CSV creation. Any unauthenticated user can therefore execute commands on the system under the same privileges as the web application, which typically runs under root at the TerraMaster Operating System.

tags | exploit, remote, web, shell, root, php, code execution
advisories | CVE-2020-28188, CVE-2020-35665
SHA-256 | 8935d1e9f61d6f9eb3550ec44e1a8a5d97992b91e55a7456ae2af009097db539
pfBlockerNG 2.1.4_26 Remote Code Execution
Posted Feb 27, 2023
Authored by IHTeam

pfBlockerNG version 2.1.4_26 remote code execution exploit.

tags | exploit, remote, code execution
advisories | CVE-2022-31814
SHA-256 | 4ac7bffe74c29e0dabbff18d552da8d3e73678fb8ed2b4a6a73be8d67499aebc
pfSense pfBlockerNG 2.1.4_26 Shell Upload
Posted Oct 17, 2022
Authored by IHTeam, jheysel-r7 | Site metasploit.com

This Metasploit module leverages a remote shell upload vulnerability in pfSense pfBlockerNG plugin versions 2.1.4_26 and below. Note that version 3.x is unaffected.

tags | exploit, remote, shell
advisories | CVE-2022-31814
SHA-256 | 4189e967b6b81ffffd850d9ece99fb550a29985985f2bcf2dcb9de105fffe02c
pfBlockerNG 2.1.4_26 Shell Upload
Posted Sep 26, 2022
Authored by IHTeam

pfBlockerNG version 2.1.4_26 unauthenticated remote shell upload exploit.

tags | exploit, remote, shell
SHA-256 | 1d7eee5bc1593b474c54a3d280da28d67551d6ae08d22fa5a7a679595e50b007
TerraMaster TOS 4.2.06 Remote Code Execution
Posted Dec 23, 2020
Authored by IHTeam, Ozkan Mustafa Akkus | Site metasploit.com

This Metasploit module exploits an unauthenticated command execution vulnerability in TerraMaster TOS version 4.2.06 leveraging include/makecvs.php.

tags | exploit, php
SHA-256 | 1ca4ee63f6107490fe17d396df7f0153a5c29930a496321ceec2101872db5321
TerraMaster TOS 4.2.06 Remote Code Execution
Posted Dec 23, 2020
Authored by IHTeam

TerraMaster TOS version 4.2.06 unauthenticated remote code execution exploit.

tags | exploit, remote, code execution
SHA-256 | 786b3e02ded0b491ccd7dbfa6dd55166637cec7a46e2e67caf487375718fdc42
eFront 3.6.9 SQL Injection / Authentication Bypass
Posted Oct 7, 2011
Authored by IHTeam

eFront versions 3.6.9 and below suffer from remote SQL injection, authentication bypass, and default credential vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, bypass
SHA-256 | aefe030445dc4bcb2dfa045d31d290d0aa40a079be3b8cf12a26783b16de5e9c
WordPress e-Commerce 3.8.4 SQL Injection
Posted Jul 19, 2011
Authored by IHTeam | Site ihteam.net

WordPress e-Commerce component versions 3.8.4 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 46fd9bfdf0f43fd77dcc35dcc0a07c44cd29f8484e5661fcfa428a3b99da8140
WordPress bSuite 4.0.7 Cross Site Scripting
Posted Jul 19, 2011
Authored by IHTeam | Site ihteam.net

WordPress bSuite component versions 4.0.7 and below suffer from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 702a67d37f8b156f89233911166cb93734573ecaeadf5a3ff89aba3f039a3a2e
Blind SQL Injection With Regular Expressions Attack
Posted Jun 13, 2011
Authored by IHTeam, white_sheep | Site ihteam.net

Whitepaper called Blind SQL Injection with Regular Expressions Attack.

tags | paper, sql injection
SHA-256 | 167010ab38c65a1b629b2eb5767870004cb391e155573d9cd652fbf5476b540f
SMBind 0.4.7 SQL Injection
Posted Sep 3, 2010
Authored by IHTeam

SMBind versions 0.4.7 and below suffer from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | 0da84d92d29133b3f50b81dffd38845ce1e493b4b43e77fddb677151dfde6607
WebJaxe 1.01 SQL Injection
Posted May 19, 2010
Authored by IHTeam

WebJaxe version 1.01 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | baf76c8040676580965fd4bafce665fcdeb81996c205eb23fb1738f37dde0430
ChillyCMS Blind SQL Injection
Posted May 19, 2010
Authored by IHTeam

ChillyCMS suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 980b85d1f7afe339d2817dd89e7104b182c21a62aeb259f2c75e6d8082c63503
TS Special Edition 7.0 Disclosure
Posted May 19, 2010
Authored by IHTeam

TS Special Edition versions 7.0 and below suffer from multiple disclosure vulnerabilities.

tags | exploit, vulnerability, info disclosure
SHA-256 | a8f644205955ebcb8f55e9fd34e72fb520b99c78fdc7c8ba13630a092451e3ab
CMS Made Simple 1.6.2 File Disclosure
Posted Aug 10, 2009
Authored by IHTeam | Site ihteam.net

CMS Made Simple versions 1.6.2 and below suffer from a local file disclosure vulnerability.

tags | exploit, local, info disclosure
SHA-256 | e1f75ca3639a9a2acd26c0bbe1910446e0d9fee255d4bd761931eda2c1ef8266
Don't Trust In Technology
Posted Jun 3, 2009
Authored by IHTeam | Site ihteam.net

Whitepaper called Don't Trust In Technology. Written in Italian.

tags | paper
SHA-256 | d2906d3113ef8d8b529020b8406551b2c8d905ae85b032194ee6ee467477c9ba
phpfullannu-sql.txt
Posted Sep 25, 2007
Authored by IHTeam | Site ihteam.net

phpFullAnnu version 6.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c73afb2e15ac32ad94eafe50d378f6d490a57f829113a00c457e8327e73faaec
clansphere-sql.txt
Posted Sep 25, 2007
Authored by IHTeam | Site ihteam.net

Clansphere 2007.4 suffers from a SQL injection vulnerability.

tags | exploit, sql injection
SHA-256 | c67c580183912ac663e02568f6f6a2068dd0794f790055fcadc892506c91774b
microcms-sql.txt
Posted Aug 28, 2007
Authored by IHTeam | Site notsec.com

Micro CMS version 3.5 suffers from a remote SQL injection vulnerability in revert-content.php.

tags | exploit, remote, php, sql injection
SHA-256 | c29d3299c76a688d56a44f0befb8be133a6472bdffbdcfef90f51baefdf48ed0
webchat-sql.txt
Posted Jun 29, 2007
Authored by IHTeam

WebChat version 0.78 suffers from a remote SQL injection vulnerability in login.php.

tags | exploit, remote, php, sql injection
SHA-256 | f9c0c2ae4469d42a69bf90751a7d343a58078a269d724bc6090f07149ced2a7c
vbPortal302.txt
Posted Aug 17, 2006
Authored by IHTeam

vbPortal versions 3.0.2 through 3.6.0 Beta 1 remote command execution exploit.

tags | exploit, remote
SHA-256 | 4f2b44e725163b4c26557b24e85f64feba296b6146d6e0c0715430e622688184
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close