what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 21 of 21 RSS Feed

Files Date: 2024-10-11

ABB Cylon Aspect 3.07.02 user.properties Default Credentials
Posted Oct 11, 2024
Authored by LiquidWorm | Site zeroscience.mk

ABB Cylon Aspect version 3.07.02 uses a weak set of default administrative credentials that can be guessed in remote password attacks and used to gain full control of the system.

tags | exploit, remote
SHA-256 | abdeff4284c7fe44c3e55417d31b7d1ca3841538897dfe4c0808b510db1dacc3
ABB Cylon Aspect 3.08.00 dialupSwitch.php Remote Code Execution
Posted Oct 11, 2024
Authored by LiquidWorm | Site zeroscience.mk

ABB Cylon Aspect version 3.08.00 suffers from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the MODEM HTTP POST parameter called by the dialupSwitch.php script.

tags | exploit, web, arbitrary, shell, php
SHA-256 | a4086eec7a5ee5c9db9cd5f10469f947a7061c1d4d1d322d7820c84737b04b5e
ABB Cylon Aspect 3.07.02 sshUpdate.php Unauthenticated Remote SSH Service Control
Posted Oct 11, 2024
Authored by LiquidWorm | Site zeroscience.mk

ABB Cylon Aspect version 3.07.02 suffers from a vulnerability that allows an unauthenticated attacker to enable or disable the SSH daemon by sending a POST request to sshUpdate.php with a simple JSON payload. This can be exploited to start the SSH service on the remote host without proper authentication, potentially enabling unauthorized access or stop and deny service access.

tags | exploit, remote, php
SHA-256 | b3763bcb69fec8fa8456518bda4905438794f1034a56b68246980d06fc740b58
Debian Security Advisory 5788-1
Posted Oct 11, 2024
Authored by Debian | Site debian.org

Debian Linux Security Advisory 5788-1 - Damien Schaeffer discovered a use-after-free in the Mozilla Firefox web browser, which could result in the execution of arbitrary code.

tags | advisory, web, arbitrary
systems | linux, debian
advisories | CVE-2024-9680
SHA-256 | 71cf6e08a29d64dd05cec8da672d495e697c717f5050845adf6c9632bc54af0a
Ubuntu Security Notice USN-7020-4
Posted Oct 11, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7020-4 - Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system.

tags | advisory, kernel
systems | linux, ubuntu
advisories | CVE-2024-41009, CVE-2024-42224
SHA-256 | 7bdc12f76ce92161568b6661bc383554aeb8e9e2644aeb9eb55bcc840b9a28c2
Ubuntu Security Notice USN-7062-1
Posted Oct 11, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 7062-1 - It was discovered that libgsf incorrectly handled certain Compound Document Binary files. If a user or automated system were tricked into opening a specially crafted file, a remote attacker could possibly use this issue to execute arbitrary code.

tags | advisory, remote, arbitrary
systems | linux, ubuntu
advisories | CVE-2024-36474
SHA-256 | e08b2d1a8c1054fb3429eeda4d87139413be28d69b597bda91a28203871786f0
Red Hat Security Advisory 2024-7994-03
Posted Oct 11, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7994-03 - Red Hat Advanced Cluster Management for Kubernetes 2.11.3 General Availability release images, bug fixes, and updated container images.

tags | advisory
systems | linux, redhat
advisories | CVE-2024-42459
SHA-256 | 4f64e5cf12aa3f65ec367ff950438b3d267c2a4645054594527db50d828aa58d
TerraMaster TOS 4.2.29 Code Injection / Local File Inclusion
Posted Oct 11, 2024
Authored by indoushka

TerraMaster TOS version 4.2.29 suffers from a remote code injection vulnerability leveraging a local file inclusion vulnerability.

tags | exploit, remote, local, file inclusion
SHA-256 | 47788fafaa57a0578fe61fae3aba9174fdcd4e9caddb1374b93de92e53260e4a
Red Hat Security Advisory 2024-7987-03
Posted Oct 11, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7987-03 - An update is now available for Red Hat Satellite 6.15 for RHEL 8. Issues addressed include HTTP request smuggling and null pointer vulnerabilities.

tags | advisory, web, vulnerability
systems | linux, redhat
advisories | CVE-2024-1135
SHA-256 | b58d7016764ddfe17daf466f24d943858f278365518a58f25fe14223d941a26f
SolarView Compact 6.00 Code Injection
Posted Oct 11, 2024
Authored by indoushka

SolarView Compact version 6.00 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | afb7c824b8a452a7e349a92945e4f923c65efb017c72b8f15dc3710d87d468e4
Openfire 4.8.0 Code Injection
Posted Oct 11, 2024
Authored by indoushka

Openfire version 4.8.0 suffers from authentication bypass and code injection vulnerabilities.

tags | exploit, vulnerability
SHA-256 | eefc137002c1066cce87682437ffa243da616e4655906ff7e940a9880c1521fa
Red Hat Security Advisory 2024-7977-03
Posted Oct 11, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7977-03 - An update for firefox is now available for Red Hat Enterprise Linux 8. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2024-9680
SHA-256 | 5dadc8c60942a612f74731ad17bcda495796bfe8065be680e18a450bfcc6f430
MagnusBilling 6.x Code Injection
Posted Oct 11, 2024
Authored by indoushka

MagnusBilling version 6.x suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 8afee02e52dfc7e60f0795a499d4d51a65da1ef81b17761aba9000d194ee19be
Kafka UI 0.7.1 Code Injection
Posted Oct 11, 2024
Authored by indoushka

Kafka UI version 0.7.1 suffers from a remote code injection vulnerability.

tags | exploit, remote
SHA-256 | f6954aa312113773c4c6cf140221ca2fecef7f97142ccba843f932cb4517b4e9
Red Hat Security Advisory 2024-7972-03
Posted Oct 11, 2024
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2024-7972-03 - An update for Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 update is now available. The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. Red Hat Product Security has rated this update as having a security impact of Critical. Issues addressed include a code execution vulnerability.

tags | advisory, code execution
systems | linux, redhat
advisories | CVE-2024-7254
SHA-256 | dda3f88a23353ff415491ab18b600dc2473b5b33043d512eceae4eb401e8d30c
GL.iNet 4.4.3 Code Injection
Posted Oct 11, 2024
Authored by indoushka

GL.iNet version 4.4.3 suffers from authentication bypass and code injection vulnerabilities.

tags | exploit, vulnerability
SHA-256 | c0bd892d4ce8d30e3432ddef1187ae27e61ca1614db2d2530154b6a6e003a28c
Gibbon School Platform 26.0.00 Code Injection
Posted Oct 11, 2024
Authored by indoushka

Gibbon School Platform version 26.0.00 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | e4e57257a6af48db80f9631152fb25298130f59964899699bca602c17cfd7836
Craft CMS 4.4.14 Code Injection
Posted Oct 11, 2024
Authored by indoushka

Craft CMS version 4.4.14 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 1f149768386bf46995caf4d51e649f8b66d41ec64b6663664584c8357eb34ffb
Chamilo 1.11.18 Code Injection
Posted Oct 11, 2024
Authored by indoushka

Chamilo version 1.11.18 suffers from a PHP code injection vulnerability.

tags | exploit, php
SHA-256 | 96e2fd6800e4eae0de444f883558a648f96062c2ef4ccf1b635571eb64c66dde
Artica Proxy 4.40 Code Injection
Posted Oct 11, 2024
Authored by indoushka

Artica Proxy version 4.40 suffers from a code injection vulnerability that provides a reverse shell.

tags | exploit, shell
SHA-256 | c1517d7efd5b58efb0947f3e574c94e4dff36e9127ec54ebd5658e96d60b3efb
XNU Insufficient Locking Use-After-Free
Posted Oct 11, 2024
Authored by Google Security Research, nedwill

XNU suffers from a race condition leading to a use-after-free between the NFSSVC_NFSD command and an upcall worker thread.

tags | advisory
SHA-256 | 7ffbd2f24181807ee212967faac09584f8f2b2db84a64cd1af883cc860d8e6a6
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close