exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 22 of 22 RSS Feed

Files Date: 2023-08-10

Microsoft Windows Kernel Security Descriptor Use-After-Free
Posted Aug 10, 2023
Authored by Google Security Research, mjurczyk

The Microsoft Windows Kernel CmDeleteLayeredKey may delete predefined tombstone keys, leading to security descriptor use-after-free.

tags | exploit, kernel
systems | windows
advisories | CVE-2023-35356
SHA-256 | a393bdd205b55a25a4010667d7d283c1bd373af4b7bb30a36f33608cf1edeb3f
Microsoft Windows Kernel Unsafe Reference
Posted Aug 10, 2023
Authored by Google Security Research, mjurczyk

The Microsoft Windows Kernel may reference rolled-back transacted keys through differencing hives.

tags | exploit, kernel
systems | windows
advisories | CVE-2023-35358
SHA-256 | b39149935b26f2a93874ead5ff16c8bafcc4acc7b2b341ba68ed2751bb86aa82
Microsoft Windows Kernel Unsafe Reference
Posted Aug 10, 2023
Authored by Google Security Research, mjurczyk

The Microsoft Windows Kernel may reference unbacked layered keys through registry virtualization.

tags | exploit, kernel, registry
systems | windows
advisories | CVE-2023-35357
SHA-256 | 7b5280c111b616102ccc14ddef413c7f8bbeeb1ba04df2aa047b88bdfe97d452
Microsoft Windows Kernel Arbitrary Read
Posted Aug 10, 2023
Authored by Google Security Research, mjurczyk

There is a Microsoft Windows Kernel arbitrary read that can be performed by accessing predefined keys through differencing hives.

tags | exploit, arbitrary, kernel
systems | windows
advisories | CVE-2023-35356
SHA-256 | 492807027a3cf7a8d886110c04d56bed4abbb83ec85e31ab445e48ddc7826fce
American Fuzzy Lop plus plus 4.08c
Posted Aug 10, 2023
Authored by van Hauser, thc, Heiko Eissfeldt, Andrea Fioraldi, Dominik Maier | Site github.com

Google's American Fuzzy Lop is a brute-force fuzzer coupled with an exceedingly simple but rock-solid instrumentation-guided genetic algorithm. afl++ is a superior fork to Google's afl. It has more speed, more and better mutations, more and better instrumentation, custom module support, etc.

Changes: Six changes to afl-fuzz, three to afl-cmin/afl-cmin.bash, three to afl-cc, two for frida_mode, and one for qemu_mode.
tags | tool, fuzzer
systems | unix
SHA-256 | f8d93f2343a040323b88f0d09c93be33b043bf63ba483af45510cb85aa1a2305
Packet Fence 13.0.0
Posted Aug 10, 2023
Site packetfence.org

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort sensors, isolation of problematic devices, remediation through a captive portal, and registration-based and scheduled vulnerability scans.

Changes: This is a major release with new features, enhancements and bug fixes. This release is considered ready for production use and upgrading from previous versions is strongly advised.
tags | tool, remote
systems | unix
SHA-256 | 9768895d2abdf9061c8bbb17f023fceda12f83ca9ad17d8775631683dbe7e462
OpenSSH 9.4p1
Posted Aug 10, 2023
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: This release fixes a number of bugs and adds some small features.
tags | tool, encryption
systems | linux, unix, openbsd
SHA-256 | 3608fd9088db2163ceb3e600c85ab79d0de3d221e59192ea1923e23263866a85
WordPress WP Project Manager 2.6.4 Privilege Escalation
Posted Aug 10, 2023
Authored by Chloe Chamberland, Lana Codes | Site wordfence.com

WordPress WP Project Manager plugin versions 2.6.4 and below suffer from a privilege escalation vulnerability.

tags | exploit
advisories | CVE-2023-3636
SHA-256 | 6dd9ce941c9d2d86124d386eff22150f99117b79a0948c64c5aa90dd062a66d1
Red Hat Security Advisory 2023-4590-01
Posted Aug 10, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-4590-01 - Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Issues addressed include a html injection vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-3971
SHA-256 | 6d99cb519c342de3573d10b7c2abdd10e9e77c8a8904d1787623fe50acf4092b
Ubuntu Security Notice USN-6281-1
Posted Aug 10, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6281-1 - Alvaro Munoz discovered that Velocity Engine incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code.

tags | advisory, remote, arbitrary
systems | linux, ubuntu
advisories | CVE-2020-13936
SHA-256 | 23db43eb8bc97d2334ec675fee1fd962af0c7f9139a18b2adfde72b91dce8a00
Red Hat Security Advisory 2023-4591-01
Posted Aug 10, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-4591-01 - Red Hat Update Infrastructure offers a highly scalable, highly redundant framework that enables you to manage repositories and content. It also enables cloud providers to deliver content and updates to Red Hat Enterprise Linux instances. Issues addressed include bypass and denial of service vulnerabilities.

tags | advisory, denial of service, vulnerability
systems | linux, redhat
advisories | CVE-2023-30608, CVE-2023-31047
SHA-256 | 14db831dab7107e03526b1f776e7bd32651e2bb30ecc3af1970c8c9edda92337
Ubuntu Security Notice USN-6243-2
Posted Aug 10, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6243-2 - USN-6243-1 fixed vulnerabilities in Graphite-Web. It was discovered that the applied fix was incomplete. This update fixes the problem. It was discovered that Graphite-Web incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform server-side request forgery and obtain sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.

tags | advisory, remote, web, vulnerability
systems | linux, ubuntu
advisories | CVE-2017-18638, CVE-2022-4729
SHA-256 | 25064c89e5e6fa6071d1e29c87bbdfbbcf49f4aaf0c925fc6c87f24e1474cc6e
Dynamic Journal CMS 2.5 Database Disclosure
Posted Aug 10, 2023
Authored by indoushka

Dynamic Journal CMS version 2.5 suffers from a database disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | 6116d0ba8d26a1199f0230b37e79aa84d8430cef695b9c89f015cd98d1b776ef
e2 Distr CMS 2.8.5.3 Backup Disclosure
Posted Aug 10, 2023
Authored by indoushka

e2 Distr CMS version 2.8.5.3 appears to leave backups in a world accessible directory under the document root.

tags | exploit, root, info disclosure
SHA-256 | 5433c74f920760e59a3889a4eb94f7621298cabe8eddf15f30585be24f026e98
DriverPack Solution CMS 17.11.108 Cross Site Scripting
Posted Aug 10, 2023
Authored by indoushka

DriverPack Solution CMS version 17.11.108 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | e6bbd0f2f85c5a85db0341ad4fa0a655765bd7b91a5cc41a6d0b07469ab56025
DMIS:CRI LMS 2.0 SQL Injection
Posted Aug 10, 2023
Authored by indoushka

DMIS:CRI LMS version 2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c7a9be978c284812022ebcd2e5b8b7e1823bf359cdbbc4d9eabfafd973395e9e
Discussion On Kontackt 1.18 Cross Site Scripting
Posted Aug 10, 2023
Authored by indoushka

Discussion On Kontackt The Exclusive PHP Social Network Platform version 1.18 suffers from a cross site scripting vulnerability.

tags | exploit, php, xss
SHA-256 | 7d18de8acfc063f172113a27af33ebbcf209b0dcb3d43c8ec163f7ff1adefc84
Digisha CMS 1.2.7 SQL Injection
Posted Aug 10, 2023
Authored by indoushka

Digisha CMS version 1.2.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | 0357b8aa69b46a1a9295acec3a0b2f291ae056879b51f555fe1c4f2cc1112494
DigaSell Digital Store PHP Script 1.0.0 SQL Injection
Posted Aug 10, 2023
Authored by indoushka

DigaSell Digital Store PHP Script version 1.0.0 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, php, sql injection
SHA-256 | 8729994d50fb2282a91511c1471e529be3acfb58262a0d60949d1b29f6c5d7a6
Doma CMS 1.0 Cross Site Scripting
Posted Aug 10, 2023
Authored by indoushka

Doma CMS version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f5fb597c82fd658cb3dd151e66237da23a4f5791751b5e130c5d95b1a8e129a9
Desenvolvido C3iM CMS 2.0 Cross Site Scripting
Posted Aug 10, 2023
Authored by indoushka

Desenvolvido C3iM CMS version 2.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ee75f970e155669b73118332fbaa7e9c33f33900005bfc151805b9ba771cd102
Deprixa 3.2.5 Cross Site Request Forgery
Posted Aug 10, 2023
Authored by indoushka

Deprixa version 3.2.5 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | c70b9c9d7d7cf489076ca295cf9ea99b9089c38e63f61ec0d4d7a1a30313bb09
Page 1 of 1
Back1Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    14 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    20 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close