Jacob Robles
15f624b745
Land #11304 , Add CVE-2018-1000999 to MailCleaner module
2019-02-05 07:19:32 -06:00
Brent Cook
ac94557a15
Land #11347 , add version check to Safari RCE exploit
2019-02-04 05:22:01 -06:00
Brendan Coles
6f31b1a110
Change default payload to reverse_bash
2019-02-03 06:18:31 +00:00
Brendan Coles
9c3368f325
Add Evince CBT File Command Injection module
2019-02-03 05:38:56 +00:00
Pedro Ribeiro
9070435603
Change to support the new nuuo lib
2019-01-30 21:32:33 +07:00
William Vu
b7bc52d20b
Fix HTTP/SMB mixin order to restore SSL option
...
Mixin order matters. Mixins kinda suck.
2019-01-29 11:09:34 -06:00
Pedro Ribeiro
f5afe98111
Add github and full disc URL
2019-01-24 22:01:02 +07:00
Pedro Ribeiro
2bf663cf7d
Add full disclosure URL
2019-01-24 21:59:45 +07:00
Carter Brainerd
2d1cecd4d5
Fix request pattern matching
2019-01-23 13:39:52 -05:00
Tod Beardsley
daa3076d42
Add CVE-2018-1000999 to MailCleaner module
...
See PR #11148
This adds the new CVE assigned by DWF for this vulnerability.
Note that [CVE-2018-10933](https://www.cvedetails.com/cve/CVE-2018-10933/ )
describes a vulnerability in libssh, but this one describes the issue as
it pertains to MailCleaner specifically.
2019-01-23 09:27:12 -06:00
Carter Brainerd
47fd066a29
Msftidy
2019-01-22 21:06:11 -05:00
Carter Brainerd
1f56bccf31
Small improvements from review
2019-01-22 20:46:28 -05:00
Shelby Pace
2ae6142de7
Land #11243 , Add ASan SUID Privesc
2019-01-22 15:50:53 -06:00
Pedro Ribeiro
f4aaf6c816
Add https to msf link
2019-01-22 19:14:52 +07:00
Pedro Ribeiro
fbde697e3f
Update nuuo_cms_fu.rb
2019-01-22 18:57:02 +07:00
Tim W
5fc0c66109
add version to check to safari exploit
2019-01-22 16:10:51 +08:00
Pedro Ribeiro
f336f41182
Update nuuo_cms_sqli.rb
2019-01-22 12:50:02 +07:00
Pedro Ribeiro
4e1d79ac4b
Update nuuo_cms_fu.rb
2019-01-22 12:45:47 +07:00
Pedro Ribeiro
da4bd2e9b8
Remove peer
2019-01-22 12:10:45 +07:00
Pedro Ribeiro
0685ebed76
Remove peer as that is not needed
2019-01-22 12:08:41 +07:00
Pedro Ribeiro
9a068e9221
Repair CMS installation and use getsystem
2019-01-22 11:57:54 +07:00
Pedro Ribeiro
688ee3d579
Remove tested versions since that is already on the docs
2019-01-22 11:43:33 +07:00
Pedro Ribeiro
100fd7b80a
Make description shorter
2019-01-21 17:40:50 +07:00
Pedro Ribeiro
15d4ca9070
Add CMS link and manual ranking
2019-01-21 17:33:58 +07:00
bcoles
f8de99422d
Add correct rand call
...
Co-Authored-By: pedrib <pedrib@gmail.com >
2019-01-21 17:31:23 +07:00
bcoles
5b699768fb
Add correct rand call
...
Co-Authored-By: pedrib <pedrib@gmail.com >
2019-01-21 17:31:08 +07:00
bcoles
88c74fcd40
add https for link
...
Co-Authored-By: pedrib <pedrib@gmail.com >
2019-01-21 17:30:54 +07:00
bcoles
01e510b48f
add failure tag
...
Co-Authored-By: pedrib <pedrib@gmail.com >
2019-01-21 17:30:35 +07:00
Pedro Ribeiro
bd3d6ee6bf
Create nuuo_cms_sqli.rb
2019-01-21 17:14:41 +07:00
Pedro Ribeiro
9ffff16e95
Add Nuuo CMS file upload exploit
2019-01-21 17:06:10 +07:00
Brendan Coles
060d20694d
Attribution
2019-01-20 09:18:43 +00:00
h00die
f47060870a
horde imp h3 imap_open
2019-01-18 19:43:45 -05:00
h00die
2585e4b708
horde imp h3 imap_open
2019-01-18 19:38:30 -05:00
Steve Embling
8585dacbb4
Updated to relevant references
...
Updated references to blog post and mailing list of commit proposal
Updated disclosure date to commit proposal
2019-01-18 17:01:17 +00:00
Carter Brainerd
1121ce1127
Change default filename to random
2019-01-17 20:12:53 -05:00
h00die
5d49f04948
not working horde imp imap_open
2019-01-17 19:55:42 -05:00
rsp3ar
2577160449
update print_error, add PrependFork and adjust timeout
2019-01-16 23:20:06 -08:00
Clément Notin
31a7b13c19
ms17_010_psexec: fix RHOST in "authenticating..." message
2019-01-16 11:23:21 +01:00
Brent Cook
1947bae45b
Land #11230 , add JuicyPotato local privilege escalation
2019-01-15 21:20:25 -06:00
Wei Chen
27d6fffdad
Land #11125 , Import/generate ysoserial Java serialization objects
2019-01-15 17:09:56 -06:00
h00die
a73fe9433b
land #11169 blueman priv esc on linux
2019-01-15 10:32:46 -05:00
bcoles
8c636f27d5
Update check method to confirm vulnerability
2019-01-15 11:31:31 +11:00
Wei Chen
47f8738f74
Add Imran Rashid to CVE-2018-11770 credit
2019-01-14 15:28:08 -06:00
Wei Chen
52ff0a8b75
Update exploits/linux/http/spark_unauth_rce as CVE-2018-11770
2019-01-14 15:10:29 -06:00
Carter Brainerd
8cd26b74d7
Please msftidy gods
2019-01-13 19:22:51 -05:00
Carter Brainerd
171d46db9b
Add disclosure date, more references, and authors
2019-01-13 19:11:05 -05:00
Carter Brainerd
89e8ff9c80
Update office_excel_slk.rb
2019-01-13 18:08:51 -05:00
Carter Brainerd
d88d1d0f1d
Create office_excel_slk.rb
2019-01-13 17:31:34 -05:00
Brendan Coles
c6f4eda7f9
Add ASan SUID Executable Privilege Escalation module
2019-01-12 09:14:20 +00:00
phra
e69d509bdf
chore: update description and ranking
2019-01-12 04:32:21 +01:00