Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Drupal Avatar Upload 7.x-1.0-beta8 Cross Site Scripting
https://1.bp.blogspot.com/--r13ngwGJe8/WWlvLp4DX4I/AAAAAAAAIMI/4n3jDvF3elUQ0c2WO1JA-mB24XU3pCyAACLcBGAs/s1600/h17.png
Drupal Avatar Uploader version 7.x-1.0-beta8 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Drupal Avatar Upload 7.x-1.0-beta8 Cross Site Scripting
https://1.bp.blogspot.com/--r13ngwGJe8/WWlvLp4DX4I/AAAAAAAAIMI/4n3jDvF3elUQ0c2WO1JA-mB24XU3pCyAACLcBGAs/s1600/h17.png
Drupal Avatar Uploader version 7.x-1.0-beta8 suffers from a cross site scripting vulnerability.
MD5 |
98078143a618b14b4c887f2febee24d0Download
# Exploit Title: Drupal avatar_uploader v7.x-1.0-beta8 - Cross Site Scripting (XSS)
# Date: 2022-03-22
# Author: Milad karimi
# Software Link: https://www.drupal.org/project/avatar_uploader
# Version: v7.x-1.0-beta8
# Tested on: Windows 10
# CVE: N/A
1. Description:
This plugin creates a avatar_uploader from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.
2. Proof of Concept:
http://$target/avatar_uploader.pages.inc?file=
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
WordPress Amministrazione Aperta plugin version 3.7.3 suffers from an arbitrary file read vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
WordPress Amministrazione Aperta plugin version 3.7.3 suffers from an arbitrary file read vulnerability.
MD5 |
8dd07978b438f1e9484ef164f2dc5d93Download
# Exploit Title: WordPress Plugin amministrazione-aperta 3.7.3 - Local File Read - Unauthenticated
# Google Dork: inurl:/wp-content/plugins/amministrazione-aperta/
# Date: 23-03-2022
# Exploit Author: Hassan Khan Yusufzai - Splint3r7
# Vendor Homepage: https://wordpress.org/plugins/amministrazione-aperta/
# Version: 3.7.3
# Tested on: Firefox
# Vulnerable File: dispatcher.php
# Vulnerable Code:
```
if ( isset($_GET['open']) ) {
include(ABSPATH . 'wp-content/plugins/'.$_GET['open']);
} else {
echo '
style="padding-bottom: 20px;">
';
include_once( ABSPATH . WPINC . '/feed.php' );
```
# Proof of Concept:
localhost/wp-content/plugins/amministrazione-aperta/wpgov/dispatcher.php?open=[LFI]
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Contact Form 7 5.5.6 Cross Site Scripting
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
WordPress Contact Form 7 plugin version 5.5.6 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Contact Form 7 5.5.6 Cross Site Scripting
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
WordPress Contact Form 7 plugin version 5.5.6 suffers from a cross site scripting vulnerability.
MD5 |
0b89a8f9aa88bf8e0fe15aafb9765d40Download
# Exploit Title: WordPress Plugin Contact Form 7 v5.5.6 - Cross Site Scripting (XSS)
# Date: 2022-03-22
# Author: Milad karimi
# Software Link: https://wordpress.org/plugins/contact-form-7
# Version: 5.5.6
# Tested on: Windows 11
# CVE: N/A
1. Description:
This plugin creates a Contact Form 7 from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.
2. Proof of Concept:
http://localhost/contact-form-7/admin/admin.php?page=
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Akismet Spam Protection 4.2.2 Cross Site Scripting
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
WordPress Akismet Spam Protection plugin version 4.2.2 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Akismet Spam Protection 4.2.2 Cross Site Scripting
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
WordPress Akismet Spam Protection plugin version 4.2.2 suffers from a cross site scripting vulnerability.
MD5 |
0f9b4eb385a11f168f0141c337e5913bDownload
# Exploit Title: WordPress Plugin Akismet Spam Protection v4.2.2 - Cross Site Scripting (XSS)
# Date: 2022-03-22
# Author: Milad karimi
# Software Link: https://wordpress.org/plugins/akismet
# Version: 4.2.2
# Tested on: Windows 11
# CVE: N/A
1. Description:
This plugin creates a Akismet Spam Protection from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.
2. Proof of Concept:
http://localhost/akismet/akismet.php?id=
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ProtonVPN 1.26.0 Unquoted Service Path
https://4.bp.blogspot.com/-xWCWgAV3Ny0/WWlvBhL9TTI/AAAAAAAAIKY/j6Iuv-WtlEAbM80hi5qIKa1OI4pChiwSgCLcBGAs/s1600/h124.png
ProtonVPN version 1.26.0 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
ProtonVPN 1.26.0 Unquoted Service Path
https://4.bp.blogspot.com/-xWCWgAV3Ny0/WWlvBhL9TTI/AAAAAAAAIKY/j6Iuv-WtlEAbM80hi5qIKa1OI4pChiwSgCLcBGAs/s1600/h124.png
ProtonVPN version 1.26.0 suffers from an unquoted service path vulnerability.
MD5 |
c12107cb30eb62adf4de5b85415d6148Download
# Exploit Title: ProtonVPN 1.26.0 - Unquoted Service Path
# Date: 22/03/2022
# Exploit Author: gemreda (@gemredax)
# Vendor Homepage: https://protonvpn.com/
# Software Link: https://protonvpn.com/
# Version: 1.26.0
# Tested: Windows 10 x64
# Contact: gemredax@pm.me
PS C:\Users\Emre> sc.exe qc "ProtonVPN Wireguard"
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: ProtonVPN Wireguard
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.WireGuardService.exe C:\ProgramData\ProtonVPN\WireGuard\ProtonVPN.conf
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : ProtonVPN WireGuard
DEPENDENCIES : Nsi
: TcpIp
SERVICE_START_NAME : LocalSystem
#Exploit:
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.
Source:packetstormsecurity.com
Hacking on Medium
Vulnerabilidad LPE en Windows que se niega a morir
https://cdn-images-1.medium.com/max/1511/0*HIWvwwhwFufwzBK6
PUBLICADO EN 23 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnerabilidad LPE en Windows que se niega a morir
https://cdn-images-1.medium.com/max/1511/0*HIWvwwhwFufwzBK6
PUBLICADO EN 23 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerabilidad LPE en Windows que se niega a morir
PUBLICADO EN 23 MARZO, 2022POR EHACKING
Hacking on Medium
‘Dirty Pipe’ Linux Kernel Privilege Escalation Vulnerability (CVE-2022–0847)
https://cdn-images-1.medium.com/max/612/1*EkagVhRY9G9ip_0fpnumjg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
‘Dirty Pipe’ Linux Kernel Privilege Escalation Vulnerability (CVE-2022–0847)
https://cdn-images-1.medium.com/max/612/1*EkagVhRY9G9ip_0fpnumjg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
‘Dirty Pipe’ Linux Kernel Privilege Escalation Vulnerability (CVE-2022–0847)
Introduction
Hacking on Medium
So You Want to be a Penetration Tester
https://cdn-images-1.medium.com/max/2186/1*oB8XmuUPH0UFZJ_tBg69cA.jpeg
Better work on your soft skills first
Continue reading on The Mayor »
___________________________
@hacking_Attack
@Hacking_Video
So You Want to be a Penetration Tester
https://cdn-images-1.medium.com/max/2186/1*oB8XmuUPH0UFZJ_tBg69cA.jpeg
Better work on your soft skills first
Continue reading on The Mayor »
___________________________
@hacking_Attack
@Hacking_Video
Medium
So You Want to be a Penetration Tester
Better work on your soft skills first
Hacking on Medium
Sequel HackTheBox Ctf
https://cdn-images-1.medium.com/max/800/1*7wKPc8akx5oPyBSDs3sSfg.png
writeup of Sequel room from hack the box.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Sequel HackTheBox Ctf
https://cdn-images-1.medium.com/max/800/1*7wKPc8akx5oPyBSDs3sSfg.png
writeup of Sequel room from hack the box.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sequel HackTheBox Ctf
writeup of Sequel room from hack the box.
Hacking on Medium
CYBER CRIME TRENDS 2020–2021
https://cdn-images-1.medium.com/max/2600/0*1cRUhL7R-clG63nc
Cyber criminals are taking advantage of the covid-19 pandemic as many staff work from home. criminal shifted from targeting individuals to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CYBER CRIME TRENDS 2020–2021
https://cdn-images-1.medium.com/max/2600/0*1cRUhL7R-clG63nc
Cyber criminals are taking advantage of the covid-19 pandemic as many staff work from home. criminal shifted from targeting individuals to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CYBER CRIME TRENDS 2020–2021
Cyber criminals are taking advantage of the covid-19 pandemic as many staff work from home. criminal shifted from targeting individuals to…
Hacking on Medium
Compromisso HackTheBox Ctf
https://cdn-images-1.medium.com/max/800/1*-cxgJeChe6grKkpLuJDW2A.png
writeup da sala de compromissos do hack the box.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Compromisso HackTheBox Ctf
https://cdn-images-1.medium.com/max/800/1*-cxgJeChe6grKkpLuJDW2A.png
writeup da sala de compromissos do hack the box.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Compromisso HackTheBox Ctf
writeup da sala de compromissos do hack the box.