trust is easily compromised
Showing 1 - 25 of 1,706 RSS Feed

Shell Files

DynPage 1.0 Cross Site Request Forgery / Shell Upload
Posted May 25, 2012
Authored by KedAns-Dz

DynPage version 1.0 suffers from cross site request forgery and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, csrf
MD5 | 476adc1bf90918f7ad3741caca2d770e
Acuity CMS 2.6.x Shell Upload
Posted May 20, 2012
Authored by Aung Khant | Site yehg.net

Acuity CMS version 2.6.x suffers from a shell upload vulnerability.

tags | exploit, shell
MD5 | 231d8a2326b1b67b3eacd41be37ce4d2
Concrete CMS 5.5 Shell Upload / Denial Of Service
Posted May 20, 2012
Authored by KedAns-Dz

Concrete CMS version 5.5 suffers from shell upload and denial of service vulnerabilities.

tags | exploit, denial of service, shell, vulnerability
MD5 | e5d9fdde1d792cd4bab71b4d1dbfc6ee
CMS-AhMeBa Professional Shell Upload
Posted May 20, 2012
Authored by Shinee_

CMS-AhMeBa Professional suffers from a shell upload vulnerability.

tags | exploit, shell
MD5 | 5a5f979b206f24906f399f6bcf455f81
Travelon Express CMS 6.2.2 XSS / Shell Upload / SQL Injection
Posted May 13, 2012
Authored by the_storm | Site vulnerability-lab.com

Travelon Express CMS version 6.2.2 suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, xss, sql injection
MD5 | 1862cfb5af1f9c7deba80fea4ff3383f
Efront 3.6.11 Cross Site Scripting / Shell Upload
Posted May 7, 2012
Authored by L3b-r1'z

Efront version 3.6.11 suffers from cross site scripting and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, xss
MD5 | 7be1b2a2b00aa3f584734f625363dec2
NetcatPHPShell 1.10
Posted May 7, 2012
Authored by Mr.H4rD3n

NetcatPHPShell is a PHP backdoor that can be leveraged to launch a connect-back shell.

tags | tool, shell, php, rootkit
systems | unix
MD5 | 272d6d9b88fa87a16f8660e9f2a198c4
PHP CGI Argument Injection
Posted May 6, 2012
Site metasploit.com

When run as a CGI, PHP up to version 5.3.12 and 5.4.2 is vulnerable to an argument injection vulnerability. This Metasploit module takes advantage of the -d flag to set php.ini directives to achieve code execution. From the advisory: "if there is NO unescaped '=' in the query string, the string is split on '+' (encoded space) characters, urldecoded, passed to a function that escapes shell metacharacters (the "encoded in a system-defined manner" from the RFC) and then passes them to the CGI binary."

tags | exploit, shell, cgi, php, code execution
advisories | CVE-2012-1823, OSVDB-81633
MD5 | 5ca5165adfa6f997cb7925bf7f9ad0e5
McAfee Virtual Technician MVTControl 6.3.0.1911 GetObject Vulnerability
Posted May 3, 2012
Authored by rgod, sinn3r | Site metasploit.com

This Metasploit modules exploits a vulnerability found in McAfee Virtual Technician's MVTControl. This ActiveX control can be abused by using the GetObject() function to load additional unsafe classes such as WScript.Shell, therefore allowing remote code execution under the context of the user.

tags | exploit, remote, shell, code execution, activex
MD5 | bbac038f59ff5043622883a24f875349
Rootkit Hunter 1.4.0
Posted May 1, 2012
Authored by Michael Boelen | Site rootkit.nl

Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.

Changes: This release adds eleven bugfixes, seven changes, and five new items.
tags | tool, shell, perl, integrity, rootkit
systems | netbsd, unix, solaris
MD5 | 37b1ceb79a5ff3debca335d6550ac6b0
WHMCS Scanning Tool
Posted May 1, 2012
Authored by Kernel

WHMCS scanning tool that uses Google to find systems that are possible vulnerable to shell upload.

tags | tool, shell
systems | unix
advisories | CVE-2012-0693
MD5 | 6cad0a59efaf2da811ee78105bbddc08
Opial CMS 2.0 XSS / SQL Injection / Shell Upload
Posted Apr 29, 2012
Authored by the_storm | Site vulnerability-lab.com

Opial CMS version 2.0 suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, xss, sql injection
MD5 | acccb552e07ec87ea83457bb160d54e8
Car Portal CMS 3.0 CSRF / XSS / Shell Upload
Posted Apr 26, 2012
Authored by the_storm | Site vulnerability-lab.com

Car Portal CMS version 3.0 suffers from cross site request forgery, cross site scripting, and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, xss, csrf
MD5 | 269134f27fcc15434b5e140d8ad6cc69
WordPress Organizer 1.2.1 XSS / CSRF / Shell Upload
Posted Apr 25, 2012
Authored by MustLive

WordPress Organizer version 1.2.1 suffers from cross site request forgery, cross site scripting, and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, xss, csrf
MD5 | 1636787d421ecc86016d375344c31402
Asterisk Project Security Advisory - AST-2012-004
Posted Apr 23, 2012
Authored by Jonathan Rose | Site asterisk.org

Asterisk Project Security Advisory - A user of the Asterisk Manager Interface can bypass a security check and execute shell commands when they lack permission to do so. Under normal conditions, a user should only be able to run shell commands if that user has System class authorization. Users could bypass this restriction by using the MixMonitor application with the originate action or by using either the GetVar or Status manager actions in combination with the SHELL and EVAL functions. The patch adds checks in each affected action to verify if a user has System class authorization. If the user does not have those authorizations, Asterisk rejects the action if it detects the use of any functions or applications that run system commands.

tags | advisory, shell
MD5 | 409cfec2b992f13790527da55bc20c35
HITB Magazine Volume 1 Issue 8
Posted Apr 23, 2012
Authored by hitb | Site hackinthebox.org

HITB Magazine Volume 1 Issue 8 - Topics include Online Security At The Crossroads, Reverse Shell Traffic Obfuscation, and more.

tags | shell, magazine
MD5 | 1df89d656d3099e02fa4026a50d29500
Adobe Flash Player ActionScript Launch Command Execution
Posted Apr 20, 2012
Authored by 0a29406d9794e4f9b30b3c5d6702c708 | Site metasploit.com

This Metasploit module exploits a vulnerability in Adobe Flash Player for Linux, version 10.0.12.36 and 9.0.151.0 and prior. An input validation vulnerability allows command execution when the browser loads a SWF file which contains shell metacharacters in the arguments to the ActionScript launch method. The victim must have Adobe AIR installed for the exploit to work. This Metasploit module was tested against version 10.0.12.36 (10r12_36).

tags | exploit, shell
systems | linux
advisories | CVE-2008-5499, OSVDB-50796
MD5 | afc250118d90645e4b69c0558747b599
Koprana CMS Shell Upload
Posted Apr 11, 2012
Authored by The UnKn0wN

Koprana CMS remote shell upload exploit written in PHP.

tags | exploit, remote, shell, php
MD5 | 5363b47d972d785998ba879624130b09
wicd Privilege Escalation
Posted Apr 11, 2012
Site infosecinstitute.com

wicd suffers from a privilege escalation vulnerability. Exploit that spawns a root shell and a patch are included.

tags | exploit, shell, root
MD5 | a33a9fa0bd4815a1f8f963ca6c0d50b7
w-CMS 2.0.1 CSRF / XSS / File Disclosure / Shell Upload
Posted Apr 7, 2012
Authored by Black-ID

w-CMS version 2.0.1 suffers from cross site request forgery, cross site scripting, file disclosure and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, xss, info disclosure, csrf
MD5 | cb0e721747d1bb9b991c9a540f125ba9
GetSimple 3.1 Shell Upload / Disclosure
Posted Mar 30, 2012
Authored by KedAns-Dz

GetSimple version 3.1 suffers from backup download and shell upload vulnerabilities.

tags | exploit, shell, vulnerability
MD5 | 56c851873b99c03e0f2e0aa87e8a6ef9
Havalite CMS Shell Upload / SQL Injection / Disclosure
Posted Mar 30, 2012
Authored by KedAns-Dz

Havalite CMS suffers from database disclosure, shell upload, and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, sql injection, info disclosure
MD5 | 95348caad568aa110e8a188446038792
Cisco Security Advisory 20120328-ssh
Posted Mar 29, 2012
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - The Secure Shell (SSH) server implementation in Cisco IOS Software and Cisco IOS XE Software contains a denial of service (DoS) vulnerability in the SSH version 2 (SSHv2) feature. An unauthenticated, remote attacker could exploit this vulnerability by attempting a reverse SSH login with a crafted username. Successful exploitation of this vulnerability could allow an attacker to create a DoS condition by causing the device to reload. Repeated exploits could create a sustained DoS condition. The SSH server in Cisco IOS Software and Cisco IOS XE Software is an optional service, but its use is highly recommended as a security best practice for the management of Cisco IOS devices. Devices that are not configured to accept SSHv2 connections are not affected by this vulnerability. Cisco has released free software updates that address this vulnerability.

tags | advisory, remote, denial of service, shell
systems | cisco, osx
advisories | CVE-2012-0386
MD5 | a91d87508705fbbed4ab6cf5e057b000
WebPortal CMS Beta Arbitrary File Upload
Posted Mar 29, 2012
Authored by HELLBOY

WebPortal CMS Beta suffers from a shell upload vulnerability.

tags | exploit, shell
MD5 | 2003bbd247f85337cdad3189249b356c
Open Journal Systems 2.3.6 XSS / File Manipulation / Shell Upload
Posted Mar 22, 2012
Authored by High-Tech Bridge SA | Site htbridge.ch

Open Journal Systems version 2.3.6 suffers from file manipulation, cross site scripting, and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, xss
advisories | CVE-2012-1467, CVE-2012-1468, CVE-2012-1469
MD5 | a2b8486d53d6b0c5366d35c44573a65b
Page 1 of 69
Back12345Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close