Vulnerabilities
ShadeYou service executes any file without any verification as SYSTEM user.
1 MIN READ
Vulnerabilities
ShadeYou service executes any file without any verification as SYSTEM user.
1 MIN READ
Vulnerabilities
Inside GenerateConfiguration method there is bug which leads to comand injection
1 MIN READ
Vulnerabilities
Only files digitally signed by SparkLabs can use this pipe because of usage of new X509Certificate2. But it's possible to bypass this by injecting our DLL into Viscosity.exe.
4 MIN READ
Vulnerabilities
It's possible to execute arbitrary commands using login form because exec() function is used without using escapeshellarg() or escapeshellcmd().
2 MIN READ
Vulnerabilities
Using Execute Command File we can execute commands on Scheduled system shutdown and because UPSMan is running as SYSTEM we execute them as Priveleged user.
1 MIN READ
Vulnerabilities
You can login as anyone without knowing password because of incorrect usage of wp_set_auth_cookie().
1 MIN READ
Vulnerabilities
We can pass __e value which is base64 encoded and unfortunatelly those datas are not cleaned.
2 MIN READ
Vulnerabilities
We can set command which will be executed when monitor get remote shutdown command.
1 MIN READ
From 0 to pentesting hero
It may be found on every website that allows for exporting data to CSV format. But how the text format can be used for the attack?
27-03-2019
2 MIN READ