Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

Apple Filing Protocol Login Utility

This Metasploit module attempts to bruteforce authentication credentials for AFP.

Packet Storm
#web#mac#apple#git#auth#ssl
Brocade Password Hash Enumeration

This Metasploit module extracts password hashes from certain Brocade load balancer devices.

SNMP Windows Username Enumeration

This Metasploit module will use LanManager/psProcessUsername OID values to enumerate local user accounts on a Windows/Solaris system via SNMP .

HP LaserJet Printer SNMP Enumeration

This Metasploit module allows enumeration of files previously printed. It provides details as filename, client, timestamp and username information. The default community used is "public".

VBulletin Administrator Account Creation

This Metasploit module abuses the "install/upgrade.php" component on vBulletin 4.1+ and 4.5+ to create a new administrator account, as exploited in the wild on October 2013. This Metasploit module has been tested successfully on vBulletin 4.1.5 and 4.1.0.

Control ID IDSecure Authentication Bypass

This Metasploit module exploits an improper access control vulnerability (CVE-2023-6329) in Control iD iDSecure less than or equal to v4.7.43.0. It allows an unauthenticated remote attacker to compute valid credentials and to add a new administrative user to the web interface of the product.

MS10-065 Microsoft IIS 5 NTFS Stream Authentication Bypass

This Metasploit module bypasses basic authentication for Internet Information Services (IIS). By appending the NTFS stream name to the directory name in a request, it is possible to bypass authentication.

TYPO3 Sa-2010-020 Remote File Disclosure

This Metasploit module exploits a flaw in the way the TYPO3 jumpurl feature matches hashes. Due to this flaw a Remote File Disclosure is possible by matching the juhash of 0. This flaw can be used to read any file that the web server user account has access to view.

Limesurvey Unauthenticated File Download

This Metasploit module exploits an unauthenticated file download vulnerability in limesurvey between 2.0+ and 2.06+ Build 151014. The file is downloaded as a ZIP and unzipped automatically, thus binary files can be downloaded.

MantisBT Password Reset

MantisBT before 1.3.10, 2.2.4, and 2.3.1 are vulnerable to unauthenticated password reset.