This Metasploit module serves an OSX app (as a zip) that contains no Info.plist, which bypasses gatekeeper in macOS versions prior to 11.3. If the user visits the site on…
>> AUTHOR: deepcore
Trojan.Win32.Agent.xdtv malware suffers from an insecure permissions vulnerability.
Trojan.Win32.Siscos.bqe malware suffers from an insecure permissions vulnerability.
Packed.Win32.Black.d malware suffers from having an open, unauthenticated proxy.
Anote version 1.0 suffers from a cross site scripting vulnerability that can lead to remote code execution.
Backdoor.Win32.NinjaSpy.c malware suffers from a code execution vulnerability.
Backdoor.Win32.Floder.gqe malware suffers from an insecure permissions vulnerability.
Freeter version 1.2.1 suffers from a cross site scripting vulnerability that can lead to remote code execution.
Markdown-Explorer version 0.1.1 suffers from a cross site scripting vulnerability that can lead to remote code execution.
Markright version 1.0 suffers from a cross site scripting vulnerability that can lead to remote code execution.