Home Tools Page 423

Tools

The latest hacking and hacker tools. Open source offensive and defensive security tools. Browse interactive maps of offensive security tools used by malicious actors and cybercriminals. Check out some live threat maps and malware intelligence databases.

This will be a curated list of mostly open source hacking tools. These can range from Red Teaming offensive security tools to fuzzers and debuggers for malware analysis. We are always looking for new state of the art tools that can be used for security professionals. Please feel free to send us a tool via email or one of our social media accounts.

Polkit 0.105-26 0.117-2 Privilege Escalation

Authored by J Smith Polkit version Polkit 0.105-26 0.117-2 suffers from a local privilege escalation vulnerability. advisories | CVE-2021-3560 Change Mirror Download # Exploit Title: Polkit 0.105-26 0.117-2 - Local Privilege Escalation# Date:...

XML External Entity Via MP3 File Upload On WordPress

Authored by Vallari Sharma, Archie Midha This document illustrates proof of concept exploitation of a vulnerability in WordPress versions 5.6.0 through 5.7.0 that gives a user the ability to upload...

Brother BRPrint Auditor 3.0.7 Unquoted Service Path

Authored by Brian Rodriguez Brother BRPrint Auditor version 3.0.7 suffers from an unquoted service path vulnerability. Change Mirror Download # Exploit Title: Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path# Discovery...

HashiCorp Nomad Remote Command Execution

Authored by Wyatt Dahlenburg | Site metasploit.com This Metasploit module lets you create a batch job on HashiCorp's Nomad service to spawn a shell. The default option is to use...

IPFire 2.25 Remote Code Execution

Authored by Grant Willcox, Mucahit Saratar | Site metasploit.com This Metasploit module exploits an authenticated command injection vulnerability in the /cgi-bin/pakfire.cgi web page of IPFire devices running versions 2.25 Core...

Client Management System 1.1 SQL Injection

Authored by BHAVESH KAUL Client Management System version 1.1 suffers from a remote SQL injection vulnerability. Change Mirror Download # Exploit Title: Client Management System 1.1 - 'Search' SQL Injection# Date: 14...

SAP Netweaver JAVA 7.50 Missing Authorization

Authored by Ignacio D. Favro | Site onapsis.com A malicious unauthenticated user could abuse the lack of authentication check on SAP Java P2P cluster communication in order to connect to...

Backdoor.Win32.Pazus.18 Authentication Bypass / Code Execution

Authored by malvuln | Site malvuln.com Backdoor.Win32.Pazus.18 malware suffers from bypass and code execution vulnerabilities. Change Mirror Download Discovery / credits: Malvuln - malvuln.com (c) 2021Original source: https://malvuln.com/advisory/5be13eb16018ab69157f8c8e96e7d6bf.txtContact: [email protected]: twitter.com/malvulnThreat: Backdoor.Win32.Pazus.18Vulnerability: Authentication...

Accela Civic Platform 21.1 Cross Site Scripting / Open Redirection

Authored by Abdulazeez Alaseeri Accela Civic Platform version 21.1 suffers from cross site scripting and open redirection vulnerabilities. advisories | CVE-2021-34370 Change Mirror Download # Exploit Title: Accela Civic Platform 21.1 - 'successURL'...

Accela Civic Platform 21.1 Insecure Direct Object Reference

Authored by Abdulazeez Alaseeri Accela Civic Platform version 21.1 suffers from an insecure direct object reference vulnerability. advisories | CVE-2021-34369 Change Mirror Download # Exploit Title: Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure...