Apache Continuum Arbitrary Command Execution Exploit

Disclosed: April 06, 2016

This module exploits a command injection in Apache Continuum <= 1.4.2. By injecting a command into the installation.varValue POST parameter to /continuum/saveInstallation.action, a shell can be spawned.

Novell ServiceDesk Authenticated File Upload Exploit

Disclosed: March 30, 2016

This module exploits an authenticated arbitrary file upload via directory traversal to execute code on the target. It has been tested on versions 6.5 and 7.1.0, in Windows and Linux installations of Novell ServiceDesk, as well as the Virtual Appliance provided by Novell.

HTTP Client Information Gather Exploit

Disclosed: March 22, 2016

This module gathers information about a browser that exploits might be interested in, such as OS name, browser version, plugins, etc. By default, the module will return a fake 404, but you can customize this output by changing the Custom404 datastore option, and redirect to an external web page.

MS16-032 Secondary Logon Handle Privilege Escalation Exploit

Disclosed: March 21, 2016

This module exploits the lack of sanitization of standard handles in Windows' Secondary Logon Service. The vulnerability is known to affect versions of Windows 7-10 and 2k8-2k12 32 and 64 bit. This module will only work against those versions of Windows with Powershell 2.0 or later and systems with two or more CPU cores.

Kaltura Remote PHP Code Execution Exploit

Disclosed: March 15, 2016

This module exploits an Object Injection vulnerability in Kaltura. By exploiting this vulnerability, unauthenticated users can execute arbitrary code under the context of the web server user. Kaltura has a module named keditorservices that takes user input and then uses it as an unserialized function parameter. T...

Exim "perl_startup" Privilege Escalation Exploit

Disclosed: March 10, 2016

This module exploits a Perl injection vulnerability in Exim < 4.86.2 given the presence of the "perl_startup" configuration parameter.

Cerberus Helpdesk User Hash Disclosure Exploit

Disclosed: March 07, 2016

This module extracts usernames and password hashes from the Cerberus Helpdesk through an unauthenticated access to a workers file. Verified on Version 4.2.3 Stable (Build 925) and 5.4.4

Nagios XI Chained Remote Code Execution Exploit

Disclosed: March 06, 2016

This module exploits an SQL injection, auth bypass, file upload, command injection, and privilege escalation in Nagios XI <= 5.2.7 to pop a root shell.

Apache Jetspeed Arbitrary File Upload Exploit

Disclosed: March 06, 2016

This module exploits the unsecured User Manager REST API and a ZIP file path traversal in Apache Jetspeed-2, version 2.3.0 and unknown earlier versions, to upload and execute a shell. Note: this exploit will create, use, and then delete a new admin user. Warning: in testing, exploiting the file upload clobbered ...

Ruby on Rails ActionPack Inline ERB Code Execution Exploit

Disclosed: March 01, 2016

This module exploits a remote code execution vulnerability in the inline request processor of the Ruby on Rails ActionPack component. This vulnerability allows an attacker to process ERB to the inline JSON processor, which is then rendered, permitting full RCE within the runtime, without logging an error condition.