on

SMBv3 Compression Buffer Overflow

A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself before injecting a payload into winlogon.exe.




on

Git Credential Helper Protocol Newline Injection

A git clone action can leak cached / stored credentials for github.com to example.com due to insecure handling of newlines in the credential helper protocol.




on

PTP-RAT Screen Share Proof Of Concept

PTP-RAT is a proof of concept that allows data theft via screen-share protocols. Each screen flash starts with a header. This contains a magic string, "PTP-RAT-CHUNK" followed by a sequence number. When the receiver is activated, it starts taking screenshots at twice the transmission frequency (the Nyquist rate). When it detects a valid header, it decodes the pixel colour information and waits on the next flash. As soon as a valid header is not detected, it reconstructs all the flashes and saves the result to a file. To transfer a file, you run an instance of the Rat locally on your hacktop, and set that up as a receiver. Another instance is run on the remote server and this acts as a sender. You simply click on send file, and select a file to send. The mouse pointer disappears and the screen begins to flash as the file is transmitted via the pixel colour values. At the end of the transfer, a file-save dialog appears on the receiver, and the file is saved.




on

Macs Framework 1.14f Cross Site Scripting / SQL Injection

Macs Framework version 1.14f suffers from cross site scripting and remote SQL injection vulnerabilities.




on

Centreon 19.10.5 SQL Injection

Centreon version 19.10.5 suffers from a remote SQL injection vulnerability.




on

PMB 5.6 SQL Injection

PMB version 5.6 suffers from a remote SQL injection vulnerability.




on

User Management System 2.0 SQL Injection

User Management System version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.




on

Complaint Management System 4.2 SQL Injection

Complaint Management System version 4.2 suffers a remote SQL injection vulnerability that allows for authentication bypass.




on

Online Shopping System Advanced 1.0 SQL Injection

Online Shopping System Advanced version 1.0 suffers from a remote SQL injection vulnerability.




on

Online Course Registration 2.0 SQL Injection

Online Course Registration 2.0 suffers from authentication bypass and remote SQL injection vulnerabilities.




on

Geeklog 2.2.1 SQL Injection

Geeklog version 2.2.1 suffers from a remote SQL injection vulnerability.




on

Project Open CMS 5.0.3 Cross Site Scripting / SQL Injection

Project Open CMS version 5.0.3 suffers from cross site scripting and remote SQL injection vulnerabilities.




on

School ERP Pro 1.0 SQL Injection

School ERP Pro version 1.0 suffers from a remote SQL injection vulnerability.




on

Open-AudIT 3.2.2 Command Injection / SQL Injection

Open-AudIT version 3.2.2 suffers from OS command injection, arbitrary file upload, and remote SQL injection vulnerabilities.




on

hits script 1.0 SQL Injection

hits script version 1.0 suffers from a remote SQL injection vulnerability.




on

iJoomla AdAgency 6.0.9 SQL Injection

iJoomla AdAgency component version 6.0.9 suffers from a remote SQL injection vulnerability.




on

Fishing Reservation System SQL Injection

Fishing Reservation System suffers from multiple remote SQL injection vulnerabilities.




on

addressbook 9.0.0.1 SQL Injection

addressbook version 9.0.0.1 suffers from a remote SQL injection vulnerability.




on

Online Scheduling System 1.0 SQL Injection

Online Scheduling System version 1.0 suffers from a remote SQL injection vulnerability.




on

Pisay Online E-Learning System 1.0 SQL Injection / Code Execution

Pisay Online E-Learning System version 1.0 suffers from remote SQL Injection and code execution vulnerabilities.




on

YesWiki cercopitheque 2020.04.18.1 SQL Injection

YesWiki cercopitheque version 2020.04.18.1 suffers from a remote SQL injection vulnerability.




on

Online Clothing Store 1.0 SQL Injection

Online Clothing Store version 1.0 suffers from a remote SQL injection vulnerability.




on

Online AgroCulture Farm Management System 1.0 SQL Injection

Online AgroCulture Farm Management System version 1.0 suffers from a remote SQL injection vulnerability.




on

School File Management System 1.0 SQL Injection

School File Management System version 1.0 suffers from a remote SQL injection vulnerability.




on

Car Park Management System 1.0 SQL Injection

Car Park Management System version 1.0 suffers a remote SQL injection vulnerability that allows for authentication bypass.




on

WordPress ChopSlider 3 SQL Injection

WordPress ChopSlider plugin version 3 suffers from a remote SQL injection vulnerability.




on

Creative Zone SQL Injection

Creative Zone suffers from a remote SQL injection vulnerability.




on

KeePass Simple Dictionary Password Enumerator

This is a simple perl script to perform dictionary attacks against the KeePass password manager.




on

RC4 Simple FILE Encryption / Decryption

Simple script to perform RC4 encryption / decryption.




on

RSA Factorization Attack Using Fermat's Algorithm

Script that performs RSA factorization attack using Fermat's algorithm.




on

SSH/SSL RSA Private Key Passphrase Dictionary Enumerator

This is a script to perform SSH/SSL RSA private key passphrase enumeration with a dictionary attack.




on

XOR File Encryption / Decryption

Script to perform basic XOR file encryption / decryption.











on

Coronavirus Has Slashed Air Pollution. This Interactive Map Shows How.






on

OpenBSD - Call For Donations





on

OpenBSD Patches Auth Bypass, Privilege Escalation Vulns