Subscribe via feed.
Posts under exploit

Nagios XI 5.7.5 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in the windowswmi, switch, and cloud-vm configuration wizards that allow an authenticated user to perform remote code execution on Nagios XI versions 5.5.6 to 5.7.5 as the apache user. Valid credentials for a Nagios XI user are required. This module has […]

ManageEngine ADSelfService Plus Unauthenticated SAML Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine AdSelfService Plus versions 6210 and below. Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ADSelfService Plus SAML endpoint. Note that the target […]

ManageEngine ADSelfService Plus Unauthenticated SAML Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine AdSelfService Plus versions 6210 and below. Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ADSelfService Plus SAML endpoint. Note that the target […]

Material Dashboard 2 SQL Injection

Posted by deepcore under exploit (1 Respond)

Material Dashboard version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

101news By Mayuri K 1.0 SQL Injection

Posted by deepcore under exploit (1 Respond)

101news By Mayuri K version 1.0 suffers from multiple remote SQL injection vulnerabilities.

Zoho ManageEngine ServiceDesk Plus 14003 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine ServiceDesk Plus versions 14003 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ServiceDesk Plus SAML endpoint. Note that the […]

Zoho ManageEngine ServiceDesk Plus 14003 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine ServiceDesk Plus versions 14003 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ServiceDesk Plus SAML endpoint. Note that the […]

Windows Kernel Registry Virtualization Memory Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from a kernel memory corruption due to an insufficient handling of predefined keys in registry virtualization.

Android Binder VMA Management Security Issues

Posted by deepcore under exploit (No Respond)

Android Binder VMA management suffers from multiple security issues.

Apache Tomcat On Ubuntu Log Init Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module targets a vulnerability in Tomcat versions 6, 7, and 8 on Debian-based distributions where these older versions provide a vulnerable tomcat init script that allows local attackers who have already gained access to the tomcat account to escalate their privileges from the tomcat user to root and fully compromise the target system.