Skip to content

Commit b2d25f8

Browse files
author
Offensive Security
committed
DB: 2015-05-07
9 new exploits
1 parent dc83e39 commit b2d25f8

12 files changed

Lines changed: 815 additions & 79 deletions

File tree

files.csv

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4164,6 +4164,7 @@ id,file,description,date,author,platform,type,port
41644164
4519,platforms/php/webapps/4519.txt,"Pindorama 0.1 client.php Remote File Inclusion Vulnerability",2007-10-11,S.W.A.T.,php,webapps,0
41654165
4520,platforms/php/webapps/4520.txt,"PicoFlat CMS <= 0.4.14 index.php Remote File Inclusion Vulnerability",2007-10-11,0in,php,webapps,0
41664166
4521,platforms/php/webapps/4521.txt,"Joomla Flash uploader 2.5.1 - Remote File Inclusion Vulnerabilities",2007-10-11,mdx,php,webapps,0
4167+
4522,platforms/hardware/remote/4522.html,"Apple iTouch/iPhone 1.1.1 - '.tif' File Remote Jailbreak Exploit",2007-10-11,"Niacin and Dre",hardware,remote,0
41674168
4523,platforms/php/webapps/4523.pl,"KwsPHP 1.0 Newsletter Module Remote SQL Injection Exploit",2007-10-11,s4mi,php,webapps,0
41684169
4524,platforms/php/webapps/4524.txt,"joomla component com_colorlab 1.0 - Remote File Inclusion Vulnerability",2007-10-12,"Mehmet Ince",php,webapps,0
41694170
4525,platforms/php/webapps/4525.pl,"TikiWiki <= 1.9.8 tiki-graph_formula.php Command Execution Exploit",2007-10-12,str0ke,php,webapps,0
@@ -33207,7 +33208,7 @@ id,file,description,date,author,platform,type,port
3320733208
36800,platforms/php/webapps/36800.txt,"Wordpress NEX-Forms < 3.0 - SQL Injection Vulnerability",2015-04-21,"Claudio Viviani",php,webapps,0
3320833209
36801,platforms/php/webapps/36801.txt,"WordPress MiwoFTP Plugin <= 1.0.5 - Arbitrary File Download",2015-04-21,"dadou dz",php,webapps,0
3320933210
36802,platforms/php/webapps/36802.txt,"WordPress Tune Library Plugin 1.5.4 - SQL Injection Vulnerability",2015-04-21,"Hannes Trunde",php,webapps,0
33210-
36803,platforms/windows/remote/36803.py,"ProFTPd 1.3.5 (mod_copy) - Remote Command Execution",2015-04-21,R-73eN,windows,remote,0
33211+
36803,platforms/linux/remote/36803.py,"ProFTPd 1.3.5 (mod_copy) - Remote Command Execution",2015-04-21,R-73eN,linux,remote,0
3321133212
36804,platforms/php/webapps/36804.pl,"MediaSuite CMS - Artibary File Disclosure Exploit",2015-04-21,"KnocKout inj3ct0r",php,webapps,0
3321233213
36805,platforms/php/webapps/36805.txt,"WordPress Community Events Plugin 1.3.5 - SQL Injection Vulnerability",2015-04-21,"Hannes Trunde",php,webapps,0
3321333214
36808,platforms/windows/remote/36808.rb,"Adobe Flash Player copyPixelsToByteArray Integer Overflow",2015-04-21,metasploit,windows,remote,0
@@ -33293,12 +33294,20 @@ id,file,description,date,author,platform,type,port
3329333294
36898,platforms/php/webapps/36898.txt,"Etano 1.20/1.22 search.php Multiple Parameter XSS",2012-03-05,"Aung Khant",php,webapps,0
3329433295
36899,platforms/php/webapps/36899.txt,"Etano 1.20/1.22 photo_search.php Multiple Parameter XSS",2012-03-05,"Aung Khant",php,webapps,0
3329533296
36900,platforms/php/webapps/36900.txt,"Etano 1.20/1.22 photo_view.php return Parameter XSS",2012-03-05,"Aung Khant",php,webapps,0
33297+
36914,platforms/php/webapps/36914.txt,"Fork CMS 3.2.x Multiple Cross Site Scripting and HTML Injection Vulnerabilities",2012-03-06,"Gjoko Krstic",php,webapps,0
33298+
36915,platforms/windows/remote/36915.txt,"NetDecision 4.6.1 Multiple Directory Traversal Vulnerabilities",2012-03-07,"Luigi Auriemma",windows,remote,0
33299+
36916,platforms/php/webapps/36916.txt,"Exponent CMS 2.0 'src' Parameter SQL Injection Vulnerability",2012-03-07,"Rob Miller",php,webapps,0
33300+
36917,platforms/php/webapps/36917.txt,"OSClass 2.3.x Directory Traversal and Arbitrary File Upload Vulnerabilities",2012-03-07,"Filippo Cavallarin",php,webapps,0
3329633301
36909,platforms/windows/local/36909.rb,"RM Downloader 2.7.5.400 - Local Buffer Overflow (MSF)",2015-05-04,"TUNISIAN CYBER",windows,local,0
3329733302
36910,platforms/php/webapps/36910.txt,"Open Realty 2.5.x 'select_users_template' Parameter Local File Include Vulnerability",2012-03-05,"Aung Khant",php,webapps,0
3329833303
36911,platforms/php/webapps/36911.txt,"11in1 CMS 1.2.1 admin/comments topicID Parameter SQL Injection",2012-03-05,"Chokri B.A",php,webapps,0
3329933304
36912,platforms/php/webapps/36912.txt,"11in1 CMS 1.2.1 admin/tps id Parameter SQL Injection",2012-03-05,"Chokri B.A",php,webapps,0
33305+
36913,platforms/php/webapps/36913.pl,"Joomla! 'redirect.php' SQL Injection Vulnerability",2012-03-05,"Colin Wong",php,webapps,0
3330033306
36903,platforms/ios/dos/36903.txt,"Grindr 2.1.1 iOS - Denial of Service",2015-05-04,Vulnerability-Lab,ios,dos,0
3330133307
36904,platforms/ios/webapps/36904.txt,"PhotoWebsite 3.1 iOS - File Include Web Vulnerability",2015-05-04,Vulnerability-Lab,ios,webapps,0
33308+
36920,platforms/windows/local/36920.py,"Mediacoder 0.8.34.5716 - Buffer Overflow SEH Exploit (.m3u)",2015-05-06,evil_comrade,windows,local,0
33309+
36921,platforms/lin_x86/shellcode/36921.c,"Linux x86 - /bin/nc -le /bin/sh -vp 17771 Shellcode (58 Bytes)",2015-05-06,"Oleg Boytsev",lin_x86,shellcode,0
33310+
36922,platforms/ios/webapps/36922.txt,"vPhoto-Album 4.2 iOS - File Include Web Vulnerability",2015-05-06,Vulnerability-Lab,ios,webapps,0
3330233311
36906,platforms/linux/dos/36906.txt,"Apache Xerces-C XML Parser < 3.1.2 - DoS POC",2015-05-04,beford,linux,dos,0
3330333312
36907,platforms/php/webapps/36907.txt,"Wordpress Ultimate Product Catalogue 3.1.2 - Multiple Persistent XSS & CSRF & File Upload",2015-05-04,"Felipe Molina",php,webapps,0
3330433313
36908,platforms/lin_x86/shellcode/36908.c,"linux/x86 - exit(0) (6 bytes)",2015-05-04,"Febriyanto Nugroho",lin_x86,shellcode,0
Lines changed: 31 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,31 +1,31 @@
1-
<!--
2-
The iPhone / iTouch tif exploit is now officially released!
3-
source: http://www.toc2rta.com/
4-
5-
So its offical we have released the tiff exploit code.
6-
You can navigate in safari to http://jailbreak.toc2rta.com
7-
on your Itouch or Iphone 1.1.1. It will crash your Safari
8-
but then you will be able to browse the file system with
9-
full read/write access. This is only for people who understand
10-
what they are doing. You will need IPHUC and some knowledge of
11-
how to put/get files.
12-
13-
TUTORIAL FOR WINDOWS http://www.ipodtouchfans.com/forums/showthread.php?t=1570
14-
15-
Check back later for a full breakdown of how the
16-
tiff works and what the future holds for Toc2rta and the
17-
Itouch & Iphone.
18-
19-
Exploit by Niacin and Dre.
20-
21-
A special thanks to Pumpkin,dinopio,davidc,natetrue,Smileydude,neimod
22-
,Nervegas,erica,roxfan,phire and the rest of the dev team for all
23-
their work that helped make this happen. You can visit the dev team's
24-
site here : http://iphone.fiveforty.net/wiki/index.php?title=Main_Page
25-
-->
26-
27-
<html>
28-
<img src="http://www.milw0rm.com/sploits/10112007-iphone.tif">
29-
</html>
30-
31-
# milw0rm.com [2007-10-11]
1+
<!--
2+
The iPhone / iTouch tif exploit is now officially released!
3+
source: http://www.toc2rta.com/
4+
5+
So its offical we have released the tiff exploit code.
6+
You can navigate in safari to http://jailbreak.toc2rta.com
7+
on your Itouch or Iphone 1.1.1. It will crash your Safari
8+
but then you will be able to browse the file system with
9+
full read/write access. This is only for people who understand
10+
what they are doing. You will need IPHUC and some knowledge of
11+
how to put/get files.
12+
13+
TUTORIAL FOR WINDOWS http://www.ipodtouchfans.com/forums/showthread.php?t=1570
14+
15+
Check back later for a full breakdown of how the
16+
tiff works and what the future holds for Toc2rta and the
17+
Itouch & Iphone.
18+
19+
Exploit by Niacin and Dre.
20+
21+
A special thanks to Pumpkin,dinopio,davidc,natetrue,Smileydude,neimod
22+
,Nervegas,erica,roxfan,phire and the rest of the dev team for all
23+
their work that helped make this happen. You can visit the dev team's
24+
site here : http://iphone.fiveforty.net/wiki/index.php?title=Main_Page
25+
-->
26+
27+
<html>
28+
<img src="https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/10112007-iphone.tif">
29+
</html>
30+
31+
# milw0rm.com [2007-10-11]

platforms/ios/dos/36903.txt

Lines changed: 162 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,162 @@
1+
Document Title:
2+
===============
3+
Grindr 2.1.1 iOS Bug Bounty #2 - Denial of Service Software Vulnerability
4+
5+
6+
References (Source):
7+
====================
8+
http://www.vulnerability-lab.com/get_content.php?id=1418
9+
10+
11+
Release Date:
12+
=============
13+
2015-05-02
14+
15+
16+
Vulnerability Laboratory ID (VL-ID):
17+
====================================
18+
1418
19+
20+
21+
Common Vulnerability Scoring System:
22+
====================================
23+
3.3
24+
25+
26+
Product & Service Introduction:
27+
===============================
28+
Grindr, which first launched in 2009, has exploded into the largest and most popular all-male location-based social network out there.
29+
With more than 5 million guys in 192 countries around the world -- and approximately 10,000 more new users downloading the app
30+
every day -- you’ll always find a new date, buddy, or friend on Grindr. Grindr is a simple app that uses your mobile device’s
31+
location-based services to show you the guys closest to you who are also on Grindr. How much of your info they see is
32+
entirely your call.
33+
34+
(Copy of the Vendor Homepage: http://grindr.com/learn-more )
35+
36+
37+
Abstract Advisory Information:
38+
==============================
39+
The Vulnerability Laboratory Research Team discovered a local and remote denial of servie vulnerability in the official Grindr v2.1.1 iOS mobile web-application.
40+
41+
42+
Vulnerability Disclosure Timeline:
43+
==================================
44+
2015-01-22: Researcher Notification & Coordination (Benjamin Kunz Mejri - Evolution Security)
45+
2015-01-22: Vendor Notification (Grinder - Bug Bounty Program)
46+
2015-02-02: Vendor Response/Feedback (Grinder - Bug Bounty Program)
47+
2015-04-01: Vendor Fix/Patch (Grindr Developer Team - Reward: x & Manager: x)
48+
2015-05-04: Public Disclosure (Vulnerability Laboratory)
49+
50+
51+
Discovery Status:
52+
=================
53+
Published
54+
55+
56+
Affected Product(s):
57+
====================
58+
Grindr LLC
59+
Product: Grinder - iOS Mobile Web Application (API) 2.2.1
60+
61+
62+
Exploitation Technique:
63+
=======================
64+
Remote
65+
66+
67+
Severity Level:
68+
===============
69+
Medium
70+
71+
72+
Technical Details & Description:
73+
================================
74+
A local and remote Denial of Service vulnerability has been discovered in the official Grindr v2.1.1 iOS mobile web-application.
75+
76+
The attacker injects a script code tag or multiple termination strings (%00%20%00%20%00) to the Display Name input field of the Edit Profile module.
77+
After the inject the service stored the malicious values as DisplayName. After the inject a random user is processing to click in the profile the
78+
contact information (facebook/twitter). After that the victim wants to copy the link and an internal service corruption occurs thats crashs the mobile app.
79+
The issue is local and remote exploitable.
80+
81+
Vulnerable Module(s):
82+
[+] Edit Profile
83+
84+
Vulnerable Parameter(s): (Input)
85+
[+] Display Name
86+
87+
Affected Module(s):
88+
[+] Contact > Social Network > Copy Link
89+
90+
91+
92+
Proof of Concept (PoC):
93+
=======================
94+
The denial of service web vulnerability can be exploited by remote attacker and local user accounts with low user interaction (click).
95+
To demonstrate the vulnerability or to reproduce the issue follow the provided information and steps below to continue.
96+
97+
Manual steps to reproduce ...
98+
1. Open the grindr mobile application
99+
2. Inject a script code tag as Display Name or use the terminated String with empty values
100+
3. Save and click in the profile the contact button (exp. facebook)
101+
4. Click to the send button ahead and push the Copy Link function
102+
5. The app service is getting terminated with an uncaught exception because of an internal parsing error
103+
104+
Note:To exploit the issue remotly the profile needs to be shared with another user and then the user only needs to push the same way the social contact button.
105+
106+
PoC Video:
107+
108+
109+
Solution - Fix & Patch:
110+
=======================
111+
First step is to prevent the issue by a secure restriction of the input. Attach a own excpetion-handling to prevent next to the insert itself.
112+
The social network accounts that are linked do not allow special chars in the username. The grindr ios app and the android app allows to register
113+
an account and to insert own scripts <html5> or null strings that corrupts the process of copy the link by an error. After the restriction has been
114+
set in the code of both (api) the issue can not anymore execute to shutdown anothers users account. Even if this issue execution is prevented that
115+
was only a solution to prevent.
116+
117+
To fix the bug ...
118+
Connect for example ios device with the running app to windows. Sync the process and reproduce the remote error and local error. Move to the iOS error
119+
folder that has been synced. Get the error attach another debugger and so on ...
120+
121+
122+
Security Risk:
123+
==============
124+
The secuirty risk of the local and remote denial of service vulnerability in the copy link function that corrupts is estimated as medium.
125+
126+
127+
Credits & Authors:
128+
==================
129+
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (bkm@evolution-sec.com) [www.vulnerability-lab.com]
130+
131+
132+
Disclaimer & Information:
133+
=========================
134+
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed
135+
or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable
136+
in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Vulnerability-Lab
137+
or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for
138+
consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break any vendor licenses,
139+
policies, deface websites, hack into databases or trade with fraud/stolen material.
140+
141+
Domains: www.vulnerability-lab.com - www.vuln-lab.com - www.evolution-sec.com
142+
Contact: admin@vulnerability-lab.com - research@vulnerability-lab.com - admin@evolution-sec.com
143+
Section: magazine.vulnerability-db.com - vulnerability-lab.com/contact.php - evolution-sec.com/contact
144+
Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab - youtube.com/user/vulnerability0lab
145+
Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rss_upcoming.php - vulnerability-lab.com/rss/rss_news.php
146+
Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list-of-bug-bounty-programs.php - vulnerability-lab.com/register/
147+
148+
Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to
149+
electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by
150+
Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other information on this website
151+
is trademark of vulnerability-lab team & the specific authors or managers. To record, list (feed), modify, use or edit our material contact
152+
(admin@vulnerability-lab.com or research@vulnerability-lab.com) to get a permission.
153+
154+
Copyright © 2015 | Vulnerability Laboratory - [Evolution Security GmbH]™
155+
156+
--
157+
VULNERABILITY LABORATORY - RESEARCH TEAM
158+
SERVICE: www.vulnerability-lab.com
159+
CONTACT: research@vulnerability-lab.com
160+
PGP KEY: http://www.vulnerability-lab.com/keys/admin@vulnerability-lab.com%280x198E9928%29.txt
161+
162+

0 commit comments

Comments
 (0)