Home Tools Page 433

Tools

The latest hacking and hacker tools. Open source offensive and defensive security tools. Browse interactive maps of offensive security tools used by malicious actors and cybercriminals. Check out some live threat maps and malware intelligence databases.

This will be a curated list of mostly open source hacking tools. These can range from Red Teaming offensive security tools to fuzzers and debuggers for malware analysis. We are always looking for new state of the art tools that can be used for security professionals. Please feel free to send us a tool via email or one of our social media accounts.

CommScope Ruckus IoT Controller 1.7.1.0 Hard-Coded Web Application Administrator Password

Authored by Jim Becher | Site korelogic.com An undocumented, administrative-level, hard-coded web application account exists in the IoT Controller OVA which cannot be changed by the customer. advisories | CVE-2021-33219 Change Mirror...

CommScope Ruckus IoT Controller 1.7.1.0 Web Application Directory Traversal

Authored by Jim Becher | Site korelogic.com A Python script (web.py) for a Dockerized webservice contains a directory traversal vulnerability, which can be leveraged by an authenticated attacker to view...

CommScope Ruckus IoT Controller 1.7.1.0 Web Application Arbitrary Read/Write

Authored by Jim Becher | Site korelogic.com The IoT Controller web application includes a NodeJS module, node-red, which has the capability for users to read or write to local files...

CommScope Ruckus IoT Controller 1.7.1.0 Undocumented Account

Authored by Jim Becher | Site korelogic.com An upgrade account is included in the IoT Controller OVA that provides the vendor undocumented access via Secure Copy (SCP). advisories | CVE-2021-33216 Change Mirror...

Selenium 3.141.59 Remote Code Execution

Authored by Jon Stratton Selenium version 3.141.59 remote code execution exploit. Change Mirror Download # Exploit Title: Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)# Date: 2021-05-27# Exploit Author: Jon Stratton# Vendor Homepage:...

WordPress LifterLMS 4.21.0 Cross Site Scripting

Authored by Captain_hook WordPress LifterLMS plugin version 4.21.0 suffers from a persistent cross site scripting vulnerability. advisories | CVE-2021-24308 Change Mirror Download # Exploit Title: WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting...

PHPFusion 9.03.50 Remote Code Execution

Authored by ThienNV, g0ldm45k PHPFusion version 9.03.50 suffers from a remote code execution vulnerability. advisories | CVE-2020-24949 Change Mirror Download # Exploit Title: PHPFusion 9.03.50 - Remote Code Execution# Date: 20/05/2021# Exploit Author:...

Trixbox 2.8.0.4 Path Traversal

Authored by Ron Jost Trixbox version 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php. advisories | CVE-2017-14537 Change Mirror Download # Exploit Title: Trixbox...

Trixbox 2.8.0.4 Remote Code Execution

Authored by Ron Jost Trixbox version 2.8.0.4 has an OS command injection vulnerability that can be leveraged via shell metacharacters in the lang parameter to /maint/modules/home/index.php. advisories | CVE-2017-14535 Change Mirror Download #...

Postbird 0.8.4 Cross Site Scripting / Local File Inclusion

Authored by Debshubra Chakraborty Postbird version 0.8.4 suffers from a javascript injection vulnerability that allows for cross site scripting and local file inclusion. advisories | CVE-2021-33570 Change Mirror Download # Exploit Title: Postbird...