exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 40 of 40 RSS Feed

Files Date: 2018-01-06 to 2018-01-07

Red Hat Security Advisory 2018-0052-01
Posted Jan 6, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-0052-01 - The rhevm-setup-plugins package adds functionality exclusive only to Red Hat Virtualization Manager, and is not available for the upstream ovirt-engine. It includes the configuration of the Red Hat Support plugin, copying downstream-only artifacts to the ISO domain, and links to the knowledgebase and other support material. The following packages have been upgraded to a later upstream version: rhevm-setup-plugins. Multiple security issues have been addressed.

tags | advisory
systems | linux, redhat
SHA-256 | d678c344102afee297f89f4c2059b29ed39418728ac1d53f6dd37834cab614a5
Red Hat Security Advisory 2018-0049-01
Posted Jan 6, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-0049-01 - The ovirt-guest-agent-docker package provides the guest agent for Red Hat Linux Atomic Host virtual machines. The guest agent allows the Red Hat Virtualization Manager to receive internal guest events and retrieve information such as the IP address and the list of installed applications from the guest. Additionally the guest agent allows the Manager to execute specific commands, such as shut down or reboot, on guest virtual machines. Security Fix: An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions. There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit. As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks.

tags | advisory
systems | linux, redhat
SHA-256 | d6bc32d089292436d17fded25a7d27d9ca20b3d8cf4a8262aa4af810375f039b
AMD PSP fTPM Remote Code Execution
Posted Jan 6, 2018
Authored by Google Security Research, Cfir Cohen

AMD PSP suffers from an fTPM remote code execution vulnerability that can be performed through a crafted EK certificate.

tags | advisory, remote, overflow, code execution
SHA-256 | f9c8289131682ca48d57d371a9ee2975ddecf1a6c3fd728766645cc43f6c8cca
GetGo Download Manager 5.3.0.2712 Proxy Buffer Overflow
Posted Jan 6, 2018
Authored by devcoinfet

GetGo Download Manager version 5.3.0.2712 'proxy' buffer overflow exploit.

tags | exploit, overflow
SHA-256 | 4fadb993b7eed6c8c18e3a734bc64b45dffa817c567a353f9cc7ee92acaf3f91
Linux x86 Reverse Shell Shellcode
Posted Jan 6, 2018
Authored by Nipun Jaswal

69 bytes small Linux x86 reverse TCP /bin/sh shell null-free shellcode that connects to 127.1.1.1:8888.

tags | shell, x86, tcp, shellcode
systems | linux
SHA-256 | a3c037f0e250702af3d83399ecd80e5c840ca64fb89654fe3614909a41547bd4
Linux x86 chmod 777 /etc/sudoers Shellcode
Posted Jan 6, 2018
Authored by Hashim Jawad

36 bytes small Linux x86 chmod 777 /etc/sudoers shellcode.

tags | x86, shellcode
systems | linux
SHA-256 | fe8090fe01e94796ba0d98828afbcf34ca9401b21d28f6c4265cc4e210b669b0
Joomla VMap 1.9.2 SQL Injection
Posted Jan 6, 2018
Authored by Bilal Kardadou

Joomla VMap extension version 1.9.2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 3f8510db7d1c035d40862caf9e2a7697ff859c81d650956aa1204650bc3523df
Joomla vRestaurant 1.9.4 SQL Injection
Posted Jan 6, 2018
Authored by Bilal Kardadou

Joomla vRestaurant extension version 1.9.4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 81e386da7525d03bdc5c7855268d520bfbf815dd04d613776eb357e15623c7ae
Joomla CMS Real Estate 1.5 SQL Injection
Posted Jan 6, 2018
Authored by Bilal Kardadou

Joomla CMS Real Estate extension version 1.5 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | bae2eb4b5eba14478edbf63d6898cb72b2867e1ac981ef7320d3021612ab9628
EMC Avamar Server / NetWorker Virtual Edition / Integrated Data Protection Applianc Bypass / Upload / Traversal
Posted Jan 6, 2018
Authored by Michael Cramer | Site emc.com

Multiple EMC products suffers from authentication bypass, file upload, and path traversal vulnerabilities. Affected includes EMC Avamar Server versions 7.1.x, 7.2.x, 7.3.x, 7.4.x, and 7.5.0, EMC NetWorker Virtual Edition (NVE) versions 9.0.x, 9.1.x, and 9.2.x, and EMC Integrated Data Protection Appliance version 2.0.

tags | advisory, vulnerability, file upload
advisories | CVE-2017-15548, CVE-2017-15549, CVE-2017-15550
SHA-256 | 3b1a9c35f09b8994e0aefdb074bb7a49a3a33215e86958f118bed2122081ebdc
VideoDuo 3.1 Cross Site Scripting
Posted Jan 6, 2018
Authored by ShanoWeb

VideoDuo Video Search Engine PHP script version 3.1 suffers from a cross site scripting vulnerability.

tags | exploit, php, xss
SHA-256 | 18f5f8ac2db57226e011d68ee30b08e3a24c5f1c249fbf62ea9d980b5e648c88
gps-server.net GPS Tracking Software 3.0 Code Injection / Password Reset
Posted Jan 6, 2018
Authored by Noman Riffat

gps-server.net GPS Tracking Software versions 3.0 and below suffer from remote code injection and password reset vulnerabilities.

tags | exploit, remote, vulnerability
advisories | CVE-2017-17097, CVE-2017-17098
SHA-256 | 30c0124c400a1693d0e840a795c18cda62cc1a17ed81aca850c7e1dbd36eb1da
Microsoft Windows Win32k DC Cache Corruption
Posted Jan 6, 2018
Authored by Tavis Ormandy, Google Security Research

A Microsoft Windows win32k vulnerability has been discovered where using SetClassLong to switch between CS_CLASSDC and CS_OWNDC corrupts DC cache.

tags | exploit
SHA-256 | d07a83757124fecff65bbde70f529b29553e02b3ecba86891ac3d31b9a1e3f28
phpRegister 1.0 Cross Site Scripting
Posted Jan 6, 2018
Authored by ShanoWeb

phpRegister version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ba0c5ed3a8bb28a49b83a7e2d2a0280cf172ea78b388c455bcf5309b39b9fbca
User Login And Management PHP Script 1.0 Cross Site Scripting
Posted Jan 6, 2018
Authored by ShanoWeb

User Login and Management PHP script version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, php, xss
SHA-256 | 16742637a2dbc582ac8f88e83c218529db4f3bbbdb82c74a256b4303c8677488
Page 2 of 2
Back12Next

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    10 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    5 Files
  • 22
    Oct 22nd
    12 Files
  • 23
    Oct 23rd
    23 Files
  • 24
    Oct 24th
    9 Files
  • 25
    Oct 25th
    10 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close