MOBOTIX Video Security Cameras Cross Site Request Forgery

The application interface MOBOTIX VMS allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Apple Quicktime FPX / PSD File Parsing Memory Corruption

Apple Quicktime versions prior to 7.7.79.80.95 suffer from .fpx and .psd file parsing memory corruption vulnerabilities. Multiple proof of concepts included.

Metaphor Stagefright Implementation

Included in this archive is a whitepaper called Metaphor – A (real) real-life Stagefright exploit. It presents a thorough research on libstagefright and new techniques used to bypass ASLR. This archive also includes the Metaphor exploit that leverages CVE-2015-3864.

Apache Jetspeed Arbitrary File Upload

This Metasploit module exploits the unsecured User Manager REST API and a ZIP file path traversal in Apache Jetspeed-2, versions 2.3.0 and unknown earlier versions, to upload and execute a shell. Note: this exploit will create, use, and then delete a new admin user. Warning: in testing, exploiting the file upload clobbered the web interface […]

[dos] – Wireshark – dissect_pktc_rekey Heap-based Out-of-Bounds Read

Wireshark – dissect_pktc_rekey Heap-based Out-of-Bounds Read

[webapps] – MOBOTIX Video Security Cameras – CSRF Add Admin Exploit

MOBOTIX Video Security Cameras – CSRF Add Admin Exploit

[remote] – Apache Jetspeed Arbitrary File Upload

Apache Jetspeed Arbitrary File Upload

[webapps] – Apache OpenMeetings 1.9.x – 3.1.0 – ZIP File path Traversal

Apache OpenMeetings 1.9.x – 3.1.0 – ZIP File path Traversal

PayPal Bug Bounty #121 – Bypass & Persistent Vulnerability

The Vulnerability Laboratory Core Research Team discovered an application-side mail encoding web vulnerability and filter bypass issue in the official PayPal Inc online-service web-application.

Cades (2016Q1) – (id) Multiple SQL Injection Vulnerabilities

An independent vulnerability laboratory researcher discovered multiple sql injection vulnerabilities in the Cades online service web-application (2016-Q1).