header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Vulnerability summary

An active network attacker (MiTM) can achieve remote code execution on a machine that runs Ikraus Anti Virus. Ikarus AV for windows uses cleartext HTTP for updates along with a CRC32 checksum and an update value for verification of the downloaded files. Also ikarus checks for a update version number which can be incremented to goad the process to update. The update process executable in ikarus called guardxup.exe guardxup.exe, send over port 80, the following request for update: GET /cgi-bin/virusutilities.pl?A=7534ED66&B=6.1.1.0.11.1.256.7601&C=1005047.2013019.2001016.98727&F=4.5.2%3bO=0%3bSP=0&E=WD-194390-VU HTTP/1.1 Accept: */* User-Agent: virusutilities(6.1,0,1005047) Host: updates.ikarus.at Connection: close The server will respond with: HTTP/1.1 200 OK Date: Sun, 23 Oct 2016 04:51:05 GMT Server: Apache/2.4.10 (Debian) mod_perl/2.0.9dev Perl/v5.20.2 Content-Disposition: inline; filename=virusutilities Content-Length: 306 Connection: close Content-Type: text/plain; charset=ISO-8859-1 <url> full http://mirror04.ikarus.at/ikarus/update/virusutilities.exe crc32 0x7534ED66 version 6.1.1.0.11.1.256.7601 </url>

Use-after-free vulnerability in Linux kernel

A Use-after-free vulnerability was found in the Linux kernel's Netlink socket subsystem – XFRM. Netlink is used to transfer information between the kernel and user-space processes. It consists of a standard sockets-based interface for user space processes and an internal kernel API for kernel modules.

Unauthorized Access Vulnerability in Trustwave SWG

Trustwave SWG allows remote attackers to send to the SWG product a SSH key that will be used by the SWG product as the SSH key to logon to the device. This allows unauthenticated user to send a POST request to /sendKey which will add the supplied ssh key to Trustwave SWG, which we can use it to login to the device.

SSD Advisory – Oracle Knowledge Management XXE Leading to a RCE

By enabling searches across a wide variety of sources, Oracle's InQuira knowledge management products offer simple and convenient ways for users to access knowledge that was once hidden in the myriad systems, applications, and databases used to store enterprise content. The vulnerable code can be found in /imws/Result.jsp which when calls, can be used to access an XML from a third-party server, this third-party server which can be under our control can be used to reference files locally present on the victim's server. To exploit the vulnerability, we will run the following 5 steps (the first 2 need to be run in the background): 'Malicious' XML External Entity (XXE) server, Listener for the gopher protocol, Attacker who steal the 'custom.xml' file, Decrypt/crack the encrypted AES password, Shell on the machine.

Public rerelease of Dahua Backdoor PoC

A vulnerability was discovered in Dahua DVR/NVR/IPC and possible all their clones. It allows an attacker to remotely download the full user database with all credentials and permissions, choose whatever admin user, copy the login names and password hashes, and use them as source to remotely login to the Dahua devices.

Vitek RCE and Information Disclosure (and possible other OEM)

A remote code execution vulnerability exists in Vitek CCTV cameras due to improper validation of user-supplied input. An attacker can send a specially crafted HTTP request to the vulnerable device to execute arbitrary code on the system. Additionally, an attacker can send a specially crafted HTTP request to the vulnerable device to disclose sensitive information such as firmware version, model name, MAC address, IP address, subnet mask, default gateway, DNS server, system time, system name, system location, admin name, admin password, user name, and user password.

Uniview RCE and export config PoC

A vulnerability in Uniview allows an attacker to remotely execute commands and export config without authentication. The attacker can send a malicious payload to the Uniview device via a specially crafted HTTP request. This payload will be executed on the device, allowing the attacker to gain access to the device and its configuration.

Recent Exploits: