SiS Windows VGA Display Manager 6.14.10.3930 – Write-What-Where PoC
SiS Windows VGA Display Manager 6.14.10.3930 – Write-What-Where PoC
Bedita 3.5.1 – XSS Vulnerabilities
Mpxplay Multimedia Commander 2.00a – .m3u Stack-Based Buffer Overflow
Viber 4.2.0 – Non-Printable Characters Handling Denial of Service Vulnerability
Ganglia Web Frontend < 3.5.1 – PHP Code Execution
Cyberoam Firewall CR500iNG-XP – 10.6.2 MR-1 – Blind SQL Injection Vulnerability
Apple OS X Entitlements Rootpipe Privilege Escalation
Edimax PS-1206MF – Web Admin Auth Bypass
PCMan FTP Server 2.0.7 – RENAME Command Buffer Overflow
This Metasploit module exploits the rootpipe vulnerability and bypasses Apple’s initial fix for the issue by injecting code into a process with the ‘admin.writeconfig’ entitlement.