sinn3r
|
6d3dcf0cef
|
Land #1912 - Fixed check for Admins SID in whoami /group output
|
2013-06-05 02:55:38 -05:00 |
sinn3r
|
a3b25fd7c9
|
Land #1909 - Novell Zenworks Mobile Device Managment exploit & auxiliary
|
2013-06-05 02:45:45 -05:00 |
sinn3r
|
0c1d46c465
|
Add more references
|
2013-06-05 02:43:43 -05:00 |
sinn3r
|
46aa6d38f8
|
Add a check for it
|
2013-06-05 02:41:03 -05:00 |
sinn3r
|
a270d37306
|
Take apart the version detection code
|
2013-06-05 02:34:35 -05:00 |
sinn3r
|
25fe03b981
|
People like this format better: IP:PORT - Message
|
2013-06-05 02:26:18 -05:00 |
sinn3r
|
02e29fff66
|
Make msftidy happy
|
2013-06-05 02:25:08 -05:00 |
sinn3r
|
35459f2657
|
Small name change, don't mind me
|
2013-06-05 02:18:11 -05:00 |
sinn3r
|
227fa4d779
|
Homie needs a default target
|
2013-06-05 02:16:59 -05:00 |
cbgabriel
|
1032663cd4
|
Fixed check for Administrators SID in whoami /group output
|
2013-06-04 18:34:06 -04:00 |
steponequit
|
ed4766dc46
|
initial commit of novell mdm modules
|
2013-06-04 09:20:10 -07:00 |
jvazquez-r7
|
3111013991
|
Minor cleanup for miniupnpd_soap_bof
|
2013-06-04 08:53:52 -05:00 |
jvazquez-r7
|
6497e5c7a1
|
Move exploit under the linux tree
|
2013-06-04 08:53:18 -05:00 |
jvazquez-r7
|
0bf2f51622
|
Land #1843, @viris exploit for CVE-2013-0230
|
2013-06-04 08:52:09 -05:00 |
Dejan Lukan
|
8ced3483de
|
Deleted some undeeded comments and used the text_rand function rather than static values.
|
2013-06-04 08:44:47 +02:00 |
sinn3r
|
ad87065b9a
|
Land #1904 - Undefined variable 'path' in tomcat_deploy_mgr.rb
|
2013-06-04 01:35:13 -05:00 |
Ruslaideemin
|
71bc06d576
|
Fix undefined variable in tomcat_mgr_deploy.rb
Exploit failed (multi/http/tomcat_mgr_deploy): NameError undefined
local variable or method `path' for #<Msf...>
[06/04/2013 10:14:03] [d(3)] core: Call stack:
modules/exploits/multi/http/tomcat_mgr_deploy.rb:253:in `exploit'
lib/msf/core/exploit_driver.rb:205:in `job_run_proc'
lib/msf/core/exploit_driver.rb:166:in `run'
lib/msf/base/simple/exploit.rb:136:in `exploit_simple'
lib/msf/base/simple/exploit.rb:161:in `exploit_simple'
lib/msf/ui/console/command_dispatcher/exploit.rb:111:in `cmd_exploit'
lib/rex/ui/text/dispatcher_shell.rb:427:in `run_command'
lib/rex/ui/text/dispatcher_shell.rb:389:in `block in run_single'
lib/rex/ui/text/dispatcher_shell.rb:383:in `each'
lib/rex/ui/text/dispatcher_shell.rb:383:in `run_single'
lib/rex/ui/text/shell.rb:200:in `run'
lib/msf/ui/web/console.rb:71:in `block in initialize'
lib/msf/core/thread_manager.rb💯in `call'
lib/msf/core/thread_manager.rb💯in `block in spawn'
Uses path instead of path_tmp in error messages.
|
2013-06-04 11:19:28 +10:00 |
jvazquez-r7
|
30a019e422
|
Land #1891, @wchen-r7's improve for ie_cgenericelement_uaf
|
2013-06-03 15:35:43 -05:00 |
Tod Beardsley
|
4cf682691c
|
New module title and description fixes
|
2013-06-03 14:40:38 -05:00 |
sinn3r
|
c705928052
|
Landing #1899 - Add OSVDB ref 85462 for esva_exec.rb
|
2013-06-03 10:40:31 -05:00 |
Steve Tornio
|
76faba60b7
|
add osvdb ref 85462
|
2013-06-03 06:16:43 -05:00 |
Steve Tornio
|
e612a3d017
|
add osvdb ref 77183
|
2013-06-03 05:42:56 -05:00 |
Dejan Lukan
|
df20e79375
|
Deleted the handle because it's not required and check() function.
|
2013-06-03 10:18:43 +02:00 |
Dejan Lukan
|
36f275d71a
|
Changed the send_request_raw into send_request_cgi function.
|
2013-06-03 10:06:24 +02:00 |
Dejan Lukan
|
675fbb3045
|
Deleted the DoS UPnP modules, because they are not relevant to the current branch.
|
2013-06-03 09:45:29 +02:00 |
Dejan Lukan
|
1ceed1e44a
|
Added corrected MiniUPnP module.
|
2013-06-03 09:37:04 +02:00 |
Dejan Lukan
|
d656360c24
|
Added CVE-2013-0230 for MiniUPnPd 1.0 stack overflow vulnerability
|
2013-06-03 09:37:03 +02:00 |
Dejan Lukan
|
39e4573d86
|
Added CVE-2013-0229 for MiniUPnPd < 1.4
|
2013-06-03 09:37:03 +02:00 |
sinn3r
|
e74c1d957f
|
Landing #1897 - Add OSVDB ref 93444 for mutiny_frontend_upload.rb
|
2013-06-03 02:15:35 -05:00 |
sinn3r
|
093830d725
|
Landing #1896 - Add OSVDB ref 82925 for symantec_web_gateway_exec.rb
|
2013-06-03 02:13:34 -05:00 |
Steve Tornio
|
c2c630c338
|
add osvdb ref 93444
|
2013-06-02 21:03:44 -05:00 |
Steve Tornio
|
bc993b76fc
|
add osvdb ref 82925
|
2013-06-02 20:43:16 -05:00 |
Steve Tornio
|
ae17e9f7b5
|
add osvdb ref 56992
|
2013-06-02 18:32:46 -05:00 |
sinn3r
|
cb33c5685f
|
Landing #1890 - Oracle WebCenter Content openWebdav() vulnerability
|
2013-06-02 12:35:40 -05:00 |
Steve Tornio
|
61c8861fcf
|
add osvdb ref
|
2013-06-02 08:33:42 -05:00 |
sinn3r
|
cc951e3412
|
Modifies the exploit a little for better stability
This patch makes sure the LFH is enabled before the CGenericElement
object is created. Triggers is also modified a little.
|
2013-06-02 03:02:42 -05:00 |
jvazquez-r7
|
1917961904
|
Land #1888, @swtornio's update for OSVDB references
|
2013-06-01 16:36:59 -05:00 |
jvazquez-r7
|
5939ca8ce4
|
Add analysis at the end of the module
|
2013-06-01 15:59:17 -05:00 |
jvazquez-r7
|
9be8971bb0
|
Add module for ZDI-13-094
|
2013-06-01 15:44:01 -05:00 |
Steve Tornio
|
8671ae9de7
|
add osvdb ref
|
2013-06-01 14:27:50 -05:00 |
Steve Tornio
|
80f1e98952
|
added osvdb refs
|
2013-06-01 07:04:43 -05:00 |
jvazquez-r7
|
f8e9535c39
|
Add ZDI reference
|
2013-05-31 20:50:53 -05:00 |
sinn3r
|
90117c322c
|
Landing #1874 - Post API cleanup
|
2013-05-31 16:15:23 -05:00 |
James Lee
|
4f6d80c813
|
Land #1804, user-settable filename for psexec
|
2013-05-31 13:34:52 -05:00 |
James Lee
|
5964d36c40
|
Fix a syntax error
Also uses a prettier syntax for setting the filename (ternary operators
are hard to read).
|
2013-05-31 13:31:36 -05:00 |
jvazquez-r7
|
146a30ec4d
|
Do minor cleanup for struts_include_params
|
2013-05-31 01:01:15 -05:00 |
jvazquez-r7
|
a7a754ae1f
|
Land #1870, @Console exploit for Struts includeParams injection
|
2013-05-31 00:59:33 -05:00 |
jvazquez-r7
|
d0489b5d1e
|
Delete some commas
|
2013-05-30 14:25:53 -05:00 |
jvazquez-r7
|
6abb591428
|
Do minor cleanup for lianja_db_net
|
2013-05-30 14:25:05 -05:00 |
jvazquez-r7
|
38e5c2bed2
|
Land #1877, @zeroSteiner's exploit for Lianja SQL
|
2013-05-30 14:23:45 -05:00 |