Subscribe via feed.
Archive for October, 2015

WinRAR Settings Import Command Execution

Posted by deepcore under exploit (No Respond)

WinRAR settings import command execution proof of concept exploit.

FTGate 2009 SR3 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

FTGate 2009 SR3 May 13 2010 Build 6.4.00 suffers from multiple cross site request forgery vulnerabilities.

PIXORD Vehicle 3G Wi-Fi Router Command Injection / Information Disclosure

Posted by deepcore under exploit (No Respond)

PIXORD Vehicle 3G Wi-Fi Router suffers from OS command injection, information disclosure, and various other vulnerabilities.

Bosch Security Systems Dinion NBN-498 XML Injection

Posted by deepcore under exploit (No Respond)

The Bosch Security Systems Dinion NBN-498 web interface suffers from an XML injection vulnerability.

FTGate 2009 SR3 Denial Of Service

Posted by deepcore under exploit (No Respond)

FTGate 2009 SR3 May 13 2010 Build 6.4.000 suffers from multiple denial of service vulnerabilities.

Simple Backdoor Shell Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits unauthenticated simple web backdoor shells by leveraging the common backdoor shell’s CMD parameter to execute commands. The SecLists project of Daniel Miessler and Jason Haddix has a lot of samples for these kind of backdoor shells which is categorized under Payloads.

Zemra Botnet CnC Web Panel Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits the CnC web panel of Zemra Botnet which contains a backdoor inside its leaked source code. Zemra is a crimeware bot that can be used to conduct DDoS attacks and is detected by Symantec as Backdoor.Zemra.

Kaseya VSA uploader.aspx Arbitrary File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an arbitrary file upload vulnerability found in Kaseya VSA versions between 7 and 9.1. A malicious unauthenticated user can upload an ASP file to an arbitrary directory leading to arbitrary code execution with IUSR privileges. This Metasploit module has been tested with Kaseya v7.0.0.17, v8.0.0.10 and v9.0.0.3.

FTGate 7 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

FTGate version 7 suffers from multiple cross site request forgery vulnerabilities.

FTGate 2009 SR3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

FTGate 2009 SR3 May 13 2010 Build 6.4.000 suffers from multiple cross site scripting vulnerabilities.