accept no compromises

Recent Files

Files RSS Feed
TM RG4332 2.7.0 Arbitrary File Disclosure
Posted Jan 27, 2017
Authored by Saeid Atabaki

TM RG4332 wireless router version 2.7.0 suffers from an arbitrary file disclosure vulnerability.

tags | exploit, arbitrary, info disclosure
GNU Screen 4.5.0 Local Root Privilege Escalation
Posted Jan 27, 2017
Authored by Xiphos Research Ltd.

GNU Screen version 4.5.0 local root privilege escalation exploit.

tags | exploit, local, root
Systemd 228 Privilege Escalation
Posted Jan 27, 2017
Authored by Sebastian Krahmer

Systemd 228 privilege escalation proof of concept exploit.

tags | exploit, proof of concept
OpenSSH 6.8 / 6.9 PTY Privilege Escalation
Posted Jan 27, 2017
Authored by Federico Bento

OpenSSH versions 6.8 and 6.9 suffer from a PTY privilege escalation vulnerability.

tags | exploit
KB Affiliate Referral PHP Script 1.0 SQL Injection
Posted Jan 27, 2017
Authored by Ihsan Sencan

KB Affiliate Referral PHP Script version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, php, sql injection
KB Login Authentication Script 1.1 SQL Injection
Posted Jan 27, 2017
Authored by Ihsan Sencan

KB Login Authentication Script version 1.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
KB Messages PHP Script 1.0 SQL Injection
Posted Jan 27, 2017
Authored by Ihsan Sencan

KB Messages PHP Script version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, php, sql injection
Polycom VVX Web Interface Privilege Escalation
Posted Jan 27, 2017
Authored by Mike Brown

The Polycom VVX web interface allows a user to change an admin's password.

tags | exploit, web
Autodesk Backburner Manager 3 Denial Of Service
Posted Jan 27, 2017
Authored by b0nd

Autodesk Backburner Manager 3 versions prior to 2016.0.0.2150 suffers from a null dereference denial of service vulnerability.

tags | exploit, denial of service
Haraka Remote Command Execution
Posted Jan 27, 2017
Authored by xychix

Haraka versions prior to 2.8.9 suffer from a remote command execution vulnerability.

tags | exploit, remote
Red Hat Security Advisory 2017-0206-01
Posted Jan 27, 2017
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2017-0206-01 - Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 56.0.2924.76. Security Fix: Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim.

tags | advisory, web, arbitrary
systems | linux, redhat
Red Hat Security Advisory 2017-0200-01
Posted Jan 27, 2017
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2017-0200-01 - puppet-swift is the Puppet module used by Red Hat OpenStack Platform director to install OpenStack Object Storage. Security Fix: An information-disclosure flaw was discovered in Red Hat OpenStack Platform director's installation of Object Storage. During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

tags | advisory
systems | linux, redhat
Red Hat Security Advisory 2017-0205-01
Posted Jan 27, 2017
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2017-0205-01 - In accordance with the Red Hat CloudForms Support Life Cycle Policy, support will end on February 28, 2017. Red Hat will not provide extended support for this product.

tags | advisory
systems | linux, redhat
Geutebrueck GCore 1.3.8.42 / 1.4.2.37 Code Execution
Posted Jan 27, 2017
Authored by Luca Cappiello, Maurice Popp | Site metasploit.com

This Metasploit module affects Geutebrueck GCore versions 1.3.8.42 and 1.4.2.37, which suffer from a remote code execution vulnerability.

tags | exploit, remote, overflow, code execution
GNU Screen 4.5.0 Privilege Escalation
Posted Jan 27, 2017
Authored by Donald Buczek

GNU Screen version 4.5.0 suffers from a local privilege escalation vulnerability.

tags | exploit, local
Man-db 2.6.7.1 Privilege Escalation
Posted Jan 27, 2017
Authored by halfdog

Man-db version 2.6.7.1 suffers from a privilege escalation vulnerability.

tags | exploit
PHPback Cross Site Scripting / SQL Injection
Posted Jan 27, 2017
Authored by Manish Tanwar

PHPback versions prior to 1.3.1 suffer from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
Web Based TimeSheet Script SQL Injection
Posted Jan 27, 2017
Authored by Ihsan Sencan

Web Based TimeSheet Script suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, web, sql injection
Linux/x86_64 execve /bin/sh Shellcode
Posted Jan 27, 2017
Authored by Robert L. Taylor

22 bytes small Linux/x86_64 execve /bin/sh shellcode.

tags | shellcode
systems | linux
DigitalSec 2017 Call For Papers
Posted Jan 27, 2017
Site sdiwc.net

The DigitalSec 2017 Call For Papers has been announced. It will take place in Kuala Lumpur, Malaysia, on July 11th through the 13th, 2017.

tags | paper, conference
Android pm_qos KASLR Bypass
Posted Jan 26, 2017
Authored by Google Security Research, laginimaineb

Android suffers from a KASLR bypass in pm_qos.

tags | exploit
Mac OS / iOS host_self_trap Use-After-Free
Posted Jan 26, 2017
Authored by Google Security Research, ianbeer

Mac OS / iOS kernels suffers from a use-after-free due to a lack of locking in host_self_trap.

tags | exploit, kernel
systems | ios
Cisco WebEx 1.0.5 Command Execution
Posted Jan 26, 2017
Authored by Tavis Ormandy, Google Security Research

Cisco WebEx version 1.0.5 suffers from a new arbitrary command execution vulnerability via a module whitelist bypass.

tags | exploit, arbitrary
systems | cisco
OpenSSL Toolkit 1.0.2k
Posted Jan 26, 2017
Site openssl.org

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide.

Changes: Bug fixes for an out-of-bounds read, a carry propagating bug, and multiple other issues.
tags | tool, encryption, protocol
systems | unix
HTTP_Upload 1.0.0.b3 Arbitrary File Upload
Posted Jan 26, 2017
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

HTTP_Upload version 1.0.0b3 fails to appropriately take into consideration more than file extensions when mitigating malicious file uploads, allowing for remote code execution.

tags | exploit, remote, code execution, file upload
View Older Files →

Recent News

News RSS Feed
Breach Site LeakedSource Apparently Raided By Feds
Posted Jan 27, 2017

tags | headline, government, usa, data loss, password
Trump's Most Senior Staff Use A Private Email Server
Posted Jan 27, 2017

tags | headline, government, email, usa, fraud
Sean Spicer Appears To Like Tweeting His Own Password
Posted Jan 27, 2017

tags | headline, government, usa, password
Man Jailed For Hacking Jennifer Lawrence
Posted Jan 26, 2017

tags | headline, hacker, privacy, data loss
Microsoft Is Helping Thai Military Government Spy On Web Users
Posted Jan 26, 2017

tags | headline, government, privacy, microsoft, spyware, thailand
Facebook Enhances Account Security With Hardware 2FA
Posted Jan 26, 2017

tags | headline, hacker, password, facebook
Trump Is Tweeting From A Hackable Android - What Can Go Wrong?
Posted Jan 26, 2017

tags | headline, hacker, government, usa, phone, flaw, google, spyware, twitter
Kaspersky Lab's Top Investigator Reportedly Arrested In Treason Probe
Posted Jan 26, 2017

tags | headline, hacker, government, malware, virus, russia
A Vigilante Is Warning Admins About Their Vulnerable DBs
Posted Jan 25, 2017

tags | headline, hacker, database, flaw
AlphaBay Dark Web Marketplace Hacked, Private Messages Leaked
Posted Jan 25, 2017

tags | headline, hacker, cybercrime, data loss, fraud
View More News →

File Archive:

January 2017

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    5 Files
  • 2
    Jan 2nd
    22 Files
  • 3
    Jan 3rd
    16 Files
  • 4
    Jan 4th
    13 Files
  • 5
    Jan 5th
    11 Files
  • 6
    Jan 6th
    9 Files
  • 7
    Jan 7th
    2 Files
  • 8
    Jan 8th
    4 Files
  • 9
    Jan 9th
    13 Files
  • 10
    Jan 10th
    16 Files
  • 11
    Jan 11th
    29 Files
  • 12
    Jan 12th
    17 Files
  • 13
    Jan 13th
    24 Files
  • 14
    Jan 14th
    3 Files
  • 15
    Jan 15th
    16 Files
  • 16
    Jan 16th
    17 Files
  • 17
    Jan 17th
    23 Files
  • 18
    Jan 18th
    21 Files
  • 19
    Jan 19th
    38 Files
  • 20
    Jan 20th
    22 Files
  • 21
    Jan 21st
    27 Files
  • 22
    Jan 22nd
    6 Files
  • 23
    Jan 23rd
    16 Files
  • 24
    Jan 24th
    28 Files
  • 25
    Jan 25th
    19 Files
  • 26
    Jan 26th
    15 Files
  • 27
    Jan 27th
    20 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

News Tags

packet storm

© 2016 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close