WordPress Core <= 4.7.4 Potential Unauthorized Password Reset (0day) [CVE-2017-8295]

2017-05-04 Thread Dawid Golunski
WordPress Core <= 4.7.4 Potential Unauthorized Password Reset (0day) [CVE-2017-8295] https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html Regards, Dawid Golunski https://legalhackers.com https://ExploitBox.io t: @dawid_golunski

Re: CVE-2017-7692: Squirrelmail 1.4.22 Remote Code Execution

2017-04-25 Thread Dawid Golunski
Thanks Regards, Dawid Golunski https://legalhackers.com https://ExploitBox.io t: @dawid_golunski On Wed, Apr 19, 2017 at 2:17 PM, Filippo Cavallarin wrote: > Hi Dawid, > ok great, I added the credits to the advisory.. now let's see what to do > with the CVEs. > > Thanks! >

PHPMailer < 5.2.20 Remote Code Execution PoC 0day Exploit (CVE-2016-10045) (Bypass of the CVE-2016-1033 patch)

2016-12-27 Thread Dawid Golunski
PHPMailer < 5.2.20 Remote Code Execution PoC 0day Exploit (CVE-2016-10045) (Bypass of the CVE-2016-1033 patch) Discovered by Dawid Golunski (@dawid_golunski) https://legalhackers.com Desc: I discovered that the current PHPMailer versions (< 5.2.20) were still vulnerable to RCE as it is po

PHPMailer < 5.2.18 Remote Code Execution [updated advisory] [CVE-2016-10033]

2016-12-27 Thread Dawid Golunski
l https://twitter.com/dawid_golunski -- Regards, Dawid Golunski https://legalhackers.com t: @dawid_

Nagios Core < 4.2.2 Curl Command Injection leading to Remote Code Execution [CVE-2016-9565]

2016-12-15 Thread Dawid Golunski
Vulnerability: Nagios Core < 4.2.2 Curl Command Injection leading to Remote Code Execution CVE-2016-9565 Discovered by: Dawid Golunski (@dawid_golunski) https://legalhackers.com Severity: High Nagios Core comes with a PHP/CGI front-end which allows to view status of the monitored hosts. T

[CVE-2016-7098] GNU Wget < 1.18 Access List Bypass / Race Condition

2016-11-23 Thread Dawid Golunski
Vulnerability: GNU Wget < 1.18 Access List Bypass / Race Condition CVE-2016-7098 Discovered by: Dawid Golunski (@dawid_golunski) https://legalhackers.com Severity: Medium GNU wget in version 1.17 and earlier, when used in mirroring/recursive mode, is affected by a Race Condition vulnerabil

Nginx (Debian-based distros) - Root Privilege Escalation (CVE-2016-1247)

2016-11-21 Thread Dawid Golunski
Vulnerability: Nginx (Debian-based distros) - Root Privilege Escalation (CVE-2016-1247) Discovered by: Dawid Golunski (@dawid_golunski) https://legalhackers.com Nginx web server packaging on Debian-based distributions such as Debian or Ubuntu was found to create log directories with insecure

MySQL / MariaDB / PerconaDB - Root Privilege Escalation Exploit ( CVE-2016-6664 / CVE-2016-5617 )

2016-11-07 Thread Dawid Golunski
CVE-2016-6664 / (Oracle)CVE-2016-5617 Vulnerability: MySQL / MariaDB / PerconaDB - Root Privilege Escalation Discovered by: Dawid Golunski @dawid_golunski https://legalhackers.com MySQL-based databases including MySQL, MariaDB and PerconaDB are affected by a privilege escalation vulnerability

CVE-2016-1240 - Tomcat packaging on Debian-based distros - Local Root Privilege Escalation

2016-10-26 Thread Dawid Golunski
/Apache-Tomcat-DebPkg-Root-PrivEsc-Exploit.html -- Regards, Dawid Golunski http://legalhackers.com

CVE-2016-1240 - Tomcat packaging on Debian-based distros - Local Root Privilege Escalation

2016-10-03 Thread Dawid Golunski
CVE: CVE-2016-1240 Vulnerability: Tomcat packaging on Debian-based distros - Local Root Privilege Escalation Affected packages: Tomcat 6/7/8 deb packages (up to 8.0.36-2) Systems affected: Debian & Ubuntu & possibly others (using the affected deb packages) Discovered by: Dawid Goluns

CVE-2016-4264 Adobe ColdFusion <= 11 XXE Vulnerability

2016-09-07 Thread Dawid Golunski
Vulnerability: Adobe ColdFusion <= 11 XXE Injection CVE: CVE-2016-4264 Vendor ID: APSB16-30 Discovered by: Dawid Golunski (http://legalhackers.com) Adobe ColdFusion in versions 11 and below is vulnerable to XXE Injection when processing untrusted office documents. Depending on a

vBulletin <= 5.2.2 Preauth Server Side Request Forgery (SSRF)

2016-08-08 Thread Dawid Golunski
etin-SSRF-Vulnerability-Exploit.txt -- Regards, Dawid Golunski http://legalhackers.com

Zabbix <= 1.8.1 SQL Injection

2010-04-01 Thread Dawid Golunski
= - Release date: April 1st, 2010 - Discovered by: Dawid Golunski - Severity: High = I. VULNERABILITY - Zabbix <= 1.8.1 SQL Injection II. BACKGROUND - Zab

Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection

2009-12-04 Thread Dawid Golunski
= - Release date: December 4th, 2009 - Discovered by: Dawid Golunski - Severity: Moderately High = I. VULNERABILITY - Invision Power Board <= 3.0.4 Local PHP File Inclusion and