This Metasploit module exploits a command injection in TimeMachine on macOS
This Metasploit module exploits a command injection in TimeMachine on macOS
WorkSuite PRM 2.4 – ‘password’ SQL Injection
Varient 1.6.1 – SQL Injection
CiuisCRM 1.6 – ‘eventType’ SQL Injection
PowerPanel Business Edition – Cross-Site Scripting
Linux/ARM64 – execve(“/bin/sh”, NULL, NULL) Shellcode (40 Bytes)
ZoneMinder 1.32.3 – Cross-Site Scripting
Linux/ARM64 – Reverse (127.0.0.1:4444/TCP) Shell (/bin/sh) + Null-Free Shellcode (128 bytes)
SAP Crystal Reports – Information Disclosure
Linux/ARM64 – Reverse (::1:4444/TCP) Shell (/bin/sh) +IPv6 Shellcode (140 bytes)