Installations running Postgres 9.3 and above have functionality which allows for the superuser and users with ‘pg_execute_server_program’ to pipe to and from an external program using COPY. This allows arbitrary…
NetNumber Titan ENUM/DNS/NP 7.9.1 – Path Traversal / Authorization Bypass
jetAudio 8.1.7.20702 Basic – ‘Enter URL’ Denial of Service (PoC)
Lotus Domino 8.5.3 – ‘EXAMINE’ Stack Buffer Overflow DEP/ASLR Bypass (NSA’s EMPHASISMINE)
Linux/x86 – execve /bin/sh Shellcode (20 bytes)
MiniFtp – ‘parseconf_load_setting’ Buffer Overflow
http://phuket.nfe.go.th/kathu/web1/file_editor/db.txt notified by SeRaVo BlackHaT
http://pattani.nfe.go.th/web1/file_editor/db.txt notified by SeRaVo BlackHaT
D-Link DWL-2600AP suffers from an authentication OS command injection vulnerability via the tftp restore functionality.
Xitami Web Server version 2.5 remote SEH buffer overflow exploit with egghunter.