Microsoft released a security bulletin (MS15-101) describing a .NET MVC denial of service vulnerability. This post analyzes the vulnerability in detail, starting from the theory and then providing a PoC…
This Metasploit module exploits a pool based buffer overflow in the atmfd.dll driver when parsing a malformed font. The vulnerability was exploited by the hacking team and disclosed on the…
This Metasploit module exploits a default credential vulnerability in ManageEngine OpManager, where a default hidden account “IntegrationUser” with administrator privileges exists. The account has a default password of “plugin” which…
Wireshark 1.12.7 – Division by Zero Crash PoC
Pligg CMS 2.0.2 – (load_data_for_search.php) SQL Injection
IKEView R60 – Buffer Overflow Local Exploit (SEH)
MS15-078 Microsoft Windows Font Driver Buffer Overflow
ManageEngine OpManager Remote Code Execution
ZeusCart 4.0 – SQL Injection
ZeusCart 4.0 – CSRF Vulnerability