Multiple vulns in Cisco UCS Director: from unauth remote access to code execution as root

2019-08-28 Thread Pedro Ribeiro
! >> Multiple critical vulnerabilities in Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data >> Discovered by Pedro Ribeiro (ped...@gmail.com) from Agile Informat

Cisco Data Center Manager multiple vulns; RCE as root

2019-07-08 Thread Pedro Ribeiro
://raw.githubusercontent.com/pedrib/PoC/master/advisories/cisco-dcnm-rce.txt >> Authentication Bypass and Arbitrary File Upload (leading to remote code execution) on Cisco Data Center Network Manager >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Se

[Multiple CVE] - Cisco Identity Services Engine unauth stored XSS to RCE as root

2019-02-04 Thread Pedro Ribeiro
ltiple vulnerabilities in Cisco Identity Services Engine (unauthenticated stored XSS to RCE as root) >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security and Dominik Czarnota (dominik.b.czarn.

[Several CVE]: NUUO CMS - multiple vulnerabilities resulting in unauth RCE

2019-01-21 Thread Pedro Ribeiro
://raw.githubusercontent.com/pedrib/PoC/master/advisories/nuuo-cms-ownage.txt >> Multiple vulnerabilities in NUUO Central Management Server >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security (http://www.agilei

[CVE-2016-6563 / VU#677427]: Dlink DIR routers HNAP Login stack buffer overflow

2016-11-08 Thread Pedro Ribeiro
/dlink-hnap-login.txt Have fun. Regards, Pedro >> Multiple vulnerabilities in Dlink DIR routers HNAP Login function (multiple routers affected) >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Informat

[CVE-2016-6600/1/2/3]: Multiple vulnerabilities (RCE, file download, etc) in WebNMS Framework 5.2 / 5.2 SP1

2016-08-09 Thread Pedro Ribeiro
lities in WebNMS Framework Server 5.2 and 5.2 SP1 >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security == Disclosure: 04/07/2016 / Last updated: 08/08/2016 >> Background on the affecte

Re: Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance

2016-08-04 Thread Pedro Ribeiro
On 04/08/16 17:46, Pedro Ribeiro wrote: > tl;dr > > Lots of RCE, hardcoded credentials, stack buffer overflow and > information disclosure in the Nuuo NVRmini and other network video > recorders of the same vendor. > These vulnerabilities also affect the NETGEAR Surveillanc

Multiple remote vulnerabilities (RCE, bof) in Nuuo NVR and NETGEAR Surveillance

2016-08-04 Thread Pedro Ribeiro
Rmini2 / NVRsolo / Crystal devices and NETGEAR ReadyNAS Surveillance application >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security (http://www.agileinfosec.co.uk/) == Disclosure: 04/08/2016 / Last

[Multiple CVE]: RCE, info disclosure, HQL injection and stored XSS in Novell Service Desk 7.1.0

2016-04-11 Thread Pedro Ribeiro
[A]: https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txt [B]: https://github.com/rapid7/metasploit-framework/pull/6769 -- >> Multiple vulnerabilities in Novell Service Desk 7.1.0, 7.0.3 and 6.5 >> Discovered by Pedro

[CERT 777024 / CVE-2016-1524/5]: RCE and file download in Netgear NMS300

2016-02-03 Thread Pedro Ribeiro
/ arbitrary file download in NETGEAR ProSafe Network Management System NMS300 >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security (http://www.agileinfosec.co.uk/) == Disclosure: 04/02/2016 / La

[ZDI-15-396] ManageEngine ServiceDesk Plus remote code execution

2015-10-05 Thread Pedro Ribeiro
in [E3]. Regards, Pedro Ribeiro Founder & Director of Research Agile Information Security [E1] http://zerodayinitiative.com/advisories/ZDI-15-396/ [E2] https://raw.githubusercontent.com/pedrib/PoC/master/advisories/ManageEngine/me_sd_file_upload_2.txt [E3] https://github.com/rapid7/metasp

Remote privesc and RCE in Kaseya Virtual System Administrator

2015-09-29 Thread Pedro Ribeiro
trator >> Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security (http://www.agileinfosec.co.uk/) == Disclosure: 23/09/2015 / Last updated: 28/09/2015 >> Background on the affected product: "Kase

Re: Windows Platform Binary Table (WPBT) - BIOS PE backdoor

2015-08-17 Thread Pedro Ribeiro
On 12 August 2015 at 18:33, Stefan Kanthak stefan.kant...@nexgo.de wrote: Kevin Beaumont kevin.beaum...@gmail.com wrote: [...] Microsoft documented a feature in Windows 8 and above called Windows Platform Binary Table. Cf. http://www.acpi.info/links.htm where WPBT is linked to

[CVE-2015-2862/2863 / CERT VU#919604] Kaseya VSA arbitrary file download / open redirect

2015-07-14 Thread Pedro Ribeiro
Administrator Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security (http://www.agileinfosec.co.uk/) == Disclosure: 13/07/2015 / Last updated: 13/07/2015 Background on the affected product: Kaseya VSA

[Multiple CVE's]: various critical vulnerabilities in SysAid Help Desk (RCE, file download, DoS, etc)

2015-06-05 Thread Pedro Ribeiro
/pull/5472 https://github.com/rapid7/metasploit-framework/pull/5473 https://github.com/rapid7/metasploit-framework/pull/5474 Multiple vulnerabilities in SysAid Help Desk 14.4 Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security

[CVE-2014-8146/8147] - ICU heap and integer overflows / I-C-U-FAIL

2015-05-05 Thread Pedro Ribeiro
-security, distro-security and Solar Designer, and will not do it again. A full copy of the advisory below can be found in my repo at https://raw.githubusercontent.com/pedrib/PoC/master/generic/i-c-u-fail.txt. Regards, Pedro Heap overflow and integer overflow in ICU library Discovered by Pedro

[CVE-2015-0779]: Novell ZenWorks Configuration Management remote code execution

2015-04-07 Thread Pedro Ribeiro
hopefully be accepted soon [2]. Regards, Pedro Remote code execution in Novell ZENworks Configuration Management 11.3.1 Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security = Disclosure: 07/04/2015

[The ManageOwnage Series, part XII]: Multiple vulnerabilities in FailOverServlet (OpManager, AppManager, IT360)

2015-01-29 Thread Pedro Ribeiro
, Applications Manager and IT360 Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security == Disclosure: 28/01/2014 / Last updated: 28/01/2014 Background on the affected products: ManageEngine OpManager is a network

Re: [The ManageOwnage Series, part X]: 0-day administrator account creation in Desktop Central

2015-01-05 Thread Pedro Ribeiro
On 31 December 2014 at 02:17, Pedro Ribeiro ped...@gmail.com wrote: Hi, This is part 10 of the ManageOwnage series. For previous parts, see [1]. This time we have a vulnerability that allows an unauthenticated user to create an administrator account, which can then be used to execute code

[The ManageOwnage Series, part XI]: Remote code execution in ServiceDesk, Asset Explorer, Support Center and IT360

2015-01-04 Thread Pedro Ribeiro
== Remote code execution / file upload in ManageEngine ServiceDesk Plus, AssetExplorer, SupportCenter Plus and IT360 Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security == Disclosure: 04/01

[The ManageOwnage Series, part X]: 0-day administrator account creation in Desktop Central

2014-12-30 Thread Pedro Ribeiro
, and a copy can be obtained from my repo [3]. Regards, Pedro Administrator account creation in ManageEngine Desktop Central / Desktop Central MSP Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security

Re: [The ManageOwnage Series, part IX]: 0-day arbitrary file download in NetFlow Analyzer and IT360

2014-12-03 Thread Pedro Ribeiro
On 30/11/2014, Pedro Ribeiro ped...@gmail.com wrote: Hi, This is part 9 of the ManageOwnage series. For previous parts see [1]. Technical details: Vulnerability: Arbitrary file download Constraints: unauthenticated in NetFlow; authenticated in IT360 Affected versions: NetFlow v8.6 to v9.9

[The ManageOwnage Series, part IX]: 0-day arbitrary file download in NetFlow Analyzer and IT360

2014-12-01 Thread Pedro Ribeiro
Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security == Disclosure: 30/11/2014 / Last updated: 30/11/2014 Background on the affected product: NetFlow Analyzer, a complete traffic analytics tool, leverages

[The ManageOwnage Series, part VII]: Super admin privesc + password DB dump in Password Manager Pro

2014-11-09 Thread Pedro Ribeiro
, Pedro Authenticated blind SQL injection in Password Manager Pro / Pro MSP Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security == Disclosure: 08/11/2014 / Last updated: 08/11/2014 Background

[The ManageOwnage series, part VIII]: Remote code execution and blind SQLi in OpManager, Social IT and IT360

2014-11-09 Thread Pedro Ribeiro
, and I have updated the full text advisory in [3]. Regards, Pedro Multiple vulnerabilities in ManageEngine OpManager, Social IT Plus and IT360 Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security

[The ManageOwnage Series, part VI]: 0day database info and superuser credential disclosure in EventLog Analyser

2014-11-06 Thread Pedro Ribeiro
, and a copy of this advisory can be found at my repo [4]. Regards, Pedro Multiple vulnerabilities in ManageEngine EventLog Analyzer Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security == Disclosure: 05/11

[CERT VU#121036 / Multiple CVEs] RCE, domain admin creds leakage and more in BMC Track-It!

2014-10-08 Thread Pedro Ribeiro
by Pedro Ribeiro (ped...@gmail.com), Agile Information Security = The application exposes several .NET remoting services on port 9010. .NET remoting is a RMI technology similar to Java RMI or CORBA which allows you

[The ManageOwnage Series, part V]: RCE / file upload / arbitrary file deletion in OpManager, Social IT and IT360

2014-09-29 Thread Pedro Ribeiro
module has been submitted and should be available soon (see pull request https://github.com/rapid7/metasploit-framework/pull/3903). Multiple vulnerabilities in ManageEngine OpManager, Social IT Plus and IT360 Discovered by Pedro Ribeiro (ped...@gmail.com), Agile Information Security

[CVE -2014-1201] Lorex security DVR ActiveX control buffer overflow

2014-01-13 Thread Pedro Ribeiro
to sales saying that technical support never contacted me back. No response. 08.01.2013 - MITRE assigns CVE-2014-1201 to this issue. 09.01.2013 - Public disclosure. All references and proof of concept can be under the lorexActivex folder in the repo at https://github.com/pedrib/PoC Regards, Pedro