Subscribe via feed.
Archive for September, 2017

Carlo Gavazzi Powersoft 2.1.1.1 Directory Traversal

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a directory traversal vulnerability found in Carlo Gavazzi Powersoft versions 2.1.1.1 and below. The vulnerability is triggered when sending a specially crafted GET request to the server. The location parameter of the GET request is not sanitized and the sendCommand.php script will automatically pull down any file requested

Indusoft Web Studio Directory Traversal

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a flaw found in Indusoft Web Studio versions 7.1 and below before SP2 Patch 4. This specific flaw allows users to browse outside of the webroot to download files found on the underlying system.

ICAffiliateTracking 1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

ICAffiliateTracking version 1.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

ICSiteBuilder 1.1 SQL Injection

Posted by deepcore under exploit (No Respond)

ICSiteBuilder version 1.1 suffers from a remote SQL injection vulnerability.

Carel PlantVisor 2.4.4 Directory Traversal

Posted by deepcore under exploit (No Respond)

Carel PlantVisor version 2.4.4 suffers from a directory traversal vulnerability.

Dameware Mini Remote Control 4.0 Username Stack Buffer Overflow

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a stack based buffer overflow vulnerability found in Dameware Mini Remote Control v4.0. The overflow is caused when sending an overly long username to the DWRCS executable listening on port 6129. The username is read into a strcpy() function causing an overwrite of the return pointer leading to arbitrary code execution.

Cloudview NMS File Upload

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a file upload vulnerability found within Cloudview NMS versions prior to 2.00b. The vulnerability is triggered by sending specialized packets to the server with directory traversal sequences to browse outside of the web root.

Alienvault OSSIM av-centerd Util.pm sync_rserver Command Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a command injection vulnerability found within the sync_rserver function in Util.pm. The vulnerability is triggered due to an incomplete blacklist during the parsing of the $uuid parameter. This allows for the escaping of a system command allowing for arbitrary command execution as root.

Microsoft Windows .NET Framework Remote Code Execution

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for a Microsoft Windows .NET Framework remote code execution vulnerability. It spawns mspaint.

Cloudview NMS 2.00b Writable Directory Traversal Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a vulnerability found in Cloudview NMS server. The software contains a directory traversal vulnerability that allows a remote attacker to write arbitrary file to the file system, which results in code execution under the context ‘SYSTEM’.