August 31, 2022Zyxel Firewall SUID Binary Privilege Escalation

This Metasploit module exploits CVE-2022-30526, a local privilege escalation vulnerability that allows a low privileged user (e.g. nobody) escalate to root. The issue stems from a suid binary that allows all users to copy files as root. This module overwr

August 31, 2022WordPress Core Cross Site Scripting / SQL Injection

The WordPress Core version 6.0.2 release addresses cross site scripting and remote SQL injection vulnerabilities.

August 29, 2022AeroCMS 0.0.1 SQL Injection

AeroCMS version 0.0.1 suffers from a remote SQL injection vulnerability.

August 25, 2022Centreon 22.04.0 Cross Site Scripting

Centreon version 22.04.0 suffers from a persistent cross site scripting vulnerability.

August 25, 2022PrestaShop Ap Pagebuilder 2.4.4 SQL Injection

PrestaShop Ap Pagebuilder module versions 2.4.4 and below suffer from a remote SQL injection vulnerability.

August 24, 2022Zimbra Zip Path Traversal

This Metasploit module POSTs a ZIP file containing path traversal characters to the administrator interface for Zimbra Collaboration Suite. If successful, it plants a JSP-based backdoor within the web directory, then executes it. The core vulnerability is

August 23, 2022Teleport 9.3.6 Command Injection

Teleport 9.3.6 is vulnerable to command injection leading to remote code execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place o

August 23, 2022WordPress Duplicator 1.4.7.2 Backup Disclosure

WordPress Duplicator plugin version 1.4.7.2 suffers from a backup disclosure vulnerability.

August 23, 202210-Strike Network Inventory Explorer 9.3 Buffer Overflow

10-Strike Network Inventory Explorer versions 9.3 and below are vulnerable to a SEH based buffer overflow which leads to code execution or local privilege escalation. The vulnerable part of the program is the functionality to add computers from a text fil

August 22, 2022Microsoft Exchange Server ChainedSerializationBinder Remote Code Execution

This Metasploit module exploits vulnerabilities within the ChainedSerializationBinder as used in Exchange Server 2019 CU10, Exchange Server 2019 CU11, Exchange Server 2016 CU21, and Exchange Server 2016 CU22 all prior to Mar22SU. Note that authentication

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow