The application interface MOBOTIX VMS allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Apple Quicktime FPX / PSD File Parsing Memory Corruption
Apple Quicktime versions prior to 7.7.79.80.95 suffer from .fpx and .psd file parsing memory corruption vulnerabilities. Multiple proof of concepts included.
Metaphor Stagefright Implementation
Included in this archive is a whitepaper called Metaphor – A (real) real-life Stagefright exploit. It presents a thorough research on libstagefright and new techniques used to bypass ASLR. This archive also includes the Metaphor exploit that leverages CVE-2015-3864.
Apache Jetspeed Arbitrary File Upload
This Metasploit module exploits the unsecured User Manager REST API and a ZIP file path traversal in Apache Jetspeed-2, versions 2.3.0 and unknown earlier versions, to upload and execute a shell. Note: this exploit will create, use, and then delete a new admin user. Warning: in testing, exploiting the file upload clobbered the web interface […]
[dos] – Wireshark – dissect_pktc_rekey Heap-based Out-of-Bounds Read
Wireshark – dissect_pktc_rekey Heap-based Out-of-Bounds Read
[webapps] – MOBOTIX Video Security Cameras – CSRF Add Admin Exploit
MOBOTIX Video Security Cameras – CSRF Add Admin Exploit
[remote] – Apache Jetspeed Arbitrary File Upload
Apache Jetspeed Arbitrary File Upload
[webapps] – Apache OpenMeetings 1.9.x – 3.1.0 – ZIP File path Traversal
Apache OpenMeetings 1.9.x – 3.1.0 – ZIP File path Traversal
PayPal Bug Bounty #121 – Bypass & Persistent Vulnerability
The Vulnerability Laboratory Core Research Team discovered an application-side mail encoding web vulnerability and filter bypass issue in the official PayPal Inc online-service web-application.
Cades (2016Q1) – (id) Multiple SQL Injection Vulnerabilities
An independent vulnerability laboratory researcher discovered multiple sql injection vulnerabilities in the Cades online service web-application (2016-Q1).