diff --git a/files.csv b/files.csv index 83cf911ac..86dc9cb5d 100755 --- a/files.csv +++ b/files.csv @@ -33305,6 +33305,7 @@ id,file,description,date,author,platform,type,port 36913,platforms/php/webapps/36913.pl,"Joomla! 'redirect.php' SQL Injection Vulnerability",2012-03-05,"Colin Wong",php,webapps,0 36903,platforms/ios/dos/36903.txt,"Grindr 2.1.1 iOS - Denial of Service",2015-05-04,Vulnerability-Lab,ios,dos,0 36904,platforms/ios/webapps/36904.txt,"PhotoWebsite 3.1 iOS - File Include Web Vulnerability",2015-05-04,Vulnerability-Lab,ios,webapps,0 +36973,platforms/php/webapps/36973.txt,"Gnuboard 4.34.20 'download.php' HTML Injection Vulnerability",2012-03-20,wh1ant,php,webapps,0 36920,platforms/windows/local/36920.py,"Mediacoder 0.8.34.5716 - Buffer Overflow SEH Exploit (.m3u)",2015-05-06,evil_comrade,windows,local,0 36921,platforms/lin_x86/shellcode/36921.c,"Linux x86 - /bin/nc -le /bin/sh -vp 17771 Shellcode (58 Bytes)",2015-05-06,"Oleg Boytsev",lin_x86,shellcode,0 36922,platforms/ios/webapps/36922.txt,"vPhoto-Album 4.2 iOS - File Include Web Vulnerability",2015-05-06,Vulnerability-Lab,ios,webapps,0 @@ -33318,6 +33319,7 @@ id,file,description,date,author,platform,type,port 36969,platforms/windows/dos/36969.txt,"Citrix 11.6.1 Licensing Administration Console Denial of Service Vulnerability",2012-03-15,Rune,windows,dos,0 36970,platforms/php/webapps/36970.txt,"JPM Article Script 6 'page2' Parameter SQL Injection Vulnerability",2012-03-16,"Vulnerability Research Laboratory",php,webapps,0 36971,platforms/java/webapps/36971.txt,"JavaBB 0.99 'userId' Parameter Cross Site Scripting Vulnerability",2012-03-18,sonyy,java,webapps,0 +36972,platforms/windows/dos/36972.py,"TYPSoft FTP Server 1.1 'APPE' Command Remote Buffer Overflow Vulnerability",2012-03-19,"brock haun",windows,dos,0 36924,platforms/ios/webapps/36924.txt,"PDF Converter & Editor 2.1 iOS - File Include Vulnerability",2015-05-06,Vulnerability-Lab,ios,webapps,0 36925,platforms/php/webapps/36925.py,"elFinder 2 Remote Command Execution (Via File Creation) Vulnerability",2015-05-06,"TUNISIAN CYBER",php,webapps,0 36926,platforms/php/webapps/36926.txt,"LeKommerce 'id' Parameter SQL Injection Vulnerability",2012-03-08,Mazt0r,php,webapps,0 @@ -33358,3 +33360,19 @@ id,file,description,date,author,platform,type,port 36962,platforms/windows/remote/36962.rb,"Adobe Flash Player NetConnection Type Confusion",2015-05-08,metasploit,windows,remote,0 36963,platforms/linux/webapps/36963.txt,"Alienvault OSSIM/USM 4.14_ 4.15_ and 5.0 - Multiple Vulnerabilities",2015-05-08,"Peter Lapp",linux,webapps,0 36964,platforms/java/remote/36964.rb,"Novell ZENworks Configuration Management Arbitrary File Upload",2015-05-08,metasploit,java,remote,443 +36974,platforms/cgi/webapps/36974.txt,"WebGlimpse 2.14.1/2.18.8 'webglimpse.cgi' Remote Command Injection Vulnerability",2012-03-20,"Kevin Perry",cgi,webapps,0 +36975,platforms/php/webapps/36975.txt,"ClassifiedsGeek.com Vacation Packages 'listing_search' Parameter SQL Injection Vulnerability",2012-03-19,r45c4l,php,webapps,0 +36976,platforms/cgi/webapps/36976.txt,"WebGlimpse 2.x 'wgarcmin.cgi' Path Disclosure Vulnerability",2012-03-18,Websecurity,cgi,webapps,0 +36977,platforms/php/webapps/36977.pl,"CreateVision CreateVision CMS 'id' Parameter SQL Injection Vulnerability",2012-03-11,"Zwierzchowski Oskar",php,webapps,0 +36978,platforms/hardware/webapps/36978.txt,"ZTE F660 - Remote Config Download",2015-05-11,"Daniel Cisa",hardware,webapps,0 +36980,platforms/windows/local/36980.py,"VideoCharge Express 3.16.3.04 - BOF Exploit",2015-05-11,evil_comrade,windows,local,0 +36981,platforms/windows/local/36981.py,"VideoCharge Professional + Express Vanilla 3.18.4.04 - BOF Exploit",2015-05-11,evil_comrade,windows,local,0 +36982,platforms/windows/local/36982.py,"VideoCharge Vanilla 3.16.4.06 - BOF Exploit",2015-05-11,evil_comrade,windows,local,0 +36984,platforms/windows/remote/36984.py,"i.FTP 2.21 - Time Field SEH Exploit",2015-05-11,"Revin Hadi Saputra",windows,remote,0 +36987,platforms/hardware/webapps/36987.pl,"D-Link DSL-500B Gen 2 - (Parental Control Configuration Panel) Stored XSS",2015-05-11,"XLabs Security",hardware,webapps,0 +36988,platforms/hardware/webapps/36988.pl,"D-Link DSL-500B Gen 2 - (URL Filter Configuration Panel) Stored XSS",2015-05-11,"XLabs Security",hardware,webapps,0 +36989,platforms/php/webapps/36989.txt,"eFront 3.6.15 - Multiple SQL Injection Vulnerabilities",2015-05-11,"Filippo Roncari",php,webapps,0 +36990,platforms/php/webapps/36990.txt,"eFront 3.6.15 - Path Traversal Vulnerability",2015-05-11,"Filippo Roncari",php,webapps,0 +36991,platforms/php/webapps/36991.txt,"eFront 3.6.15 - PHP Object Injection Vulnerability",2015-05-11,"Filippo Roncari",php,webapps,0 +36992,platforms/php/webapps/36992.txt,"Wing FTP Server Admin <= 4.4.5 - CSRF Add Arbitrary User",2015-05-11,"John Page",php,webapps,0 +36993,platforms/php/webapps/36993.txt,"SQLBuddy 1.3.3 - Path Traversal Vulnerability",2015-05-11,"John Page",php,webapps,0 diff --git a/platforms/cgi/webapps/36974.txt b/platforms/cgi/webapps/36974.txt new file mode 100755 index 000000000..952517405 --- /dev/null +++ b/platforms/cgi/webapps/36974.txt @@ -0,0 +1,9 @@ +source: http://www.securityfocus.com/bid/52627/info + +WebGlimpse is prone to a remote command-injection vulnerability. + +Attackers can exploit this issue to execute arbitrary commands in the context of the application. + +WebGlimpse versions prior to 20.20.0 are affected. + +query=%27%26command+and+arguments+go+here%26%27 \ No newline at end of file diff --git a/platforms/cgi/webapps/36976.txt b/platforms/cgi/webapps/36976.txt new file mode 100755 index 000000000..328a507b9 --- /dev/null +++ b/platforms/cgi/webapps/36976.txt @@ -0,0 +1,9 @@ +source: http://www.securityfocus.com/bid/52646/info + +WebGlimpse is prone to a path-disclosure vulnerability. + +Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks against a vulnerable computer. + +WebGlimpse 2.18.7 is vulnerable; other versions may also be affected. + +http://www.example.com/wgarcmin.cgi?NEXTPAGE=D&ID=1&DOC=1 \ No newline at end of file diff --git a/platforms/hardware/webapps/36978.txt b/platforms/hardware/webapps/36978.txt new file mode 100755 index 000000000..edf1aade4 --- /dev/null +++ b/platforms/hardware/webapps/36978.txt @@ -0,0 +1,26 @@ +/* +Exploit Title : ZTE remote configuration download +Date : 09 May 2015 +Exploit Author : Daniel Cisa +Vendor Homepage : http://wwwen.zte.com.cn/en/ +Platform : Hardware +Tested On : ZTE F660 +Firmware Version: 2.22.21P1T8S +-------------------------- + Config remote download +-------------------------- +ZTE F660 Embedded Software does not check Cookies And Credentials on POST +method so +attackers could download the config file with this post method without +authentication. + +*/ + +
+