Subscribe via feed.
Archive for December, 2022

OX App Suite 7.10.6 Cross Site Scripting / SSRF / Resource Consumption

Posted by deepcore under exploit (No Respond)

OX App Suite versions 7.10.6 and below suffer from cross site scripting, server-side request forgery, and resource exhaustion vulnerabilities.

Microsoft Exchange ProxyNotShell Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module chains two vulnerabilities on Microsoft Exchange Server that, when combined, allow an authenticated attacker to interact with the Exchange Powershell backend (CVE-2022-41040), where a deserialization flaw can be leveraged to obtain code execution (CVE-2022-41082). This exploit only supports Exchange Server 2019. These vulnerabilities were patched in November 2022.

perfSONAR 4.4.4 Open Proxy / Relay

Posted by deepcore under exploit (No Respond)

perfSONAR bundles with it a graphData.cgi script, used to graph and visualize data. There is a flaw in graphData.cgi allowing for unauthenticated users to proxy and relay HTTP/HTTPS traffic through the perfSONAR server. The vulnerability can potentially be leveraged to exfiltrate or enumerate data from internal web servers. This vulnerability was patched in perfSONAR version […]

perfSONAR 4.4.5 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

A partial blind cross site request forgery (CSRF) vulnerability exists in perfSONAR versions 4.x through 4.4.5 within the /perfsonar-graphs/ test results page. Parameters and values can be injected/passed via the URL parameter, forcing the client to connect unknowingly in the background to other sites via transparent XMLHTTPRequests. This partial blind CSRF bypasses the built-in whitelisting […]