[FD] Algorithmia MSOL - Remote Code Execution

2022-02-16 Thread ghost
up to the date of this submission Exploit Authors: Josh Sheppard & Pathfynder Inc Exploit Contact: ghost a t undervurse dot_com & josh a t pathfynder dot_io Exploit Technique: Remote CVE ID: CVE-2021-42951 1. Description A remote code execution vulnerability has been discovered in Algorith

[FD] Zepl Notebook - Sandbox Escape

2022-02-16 Thread ghost
submission Exploit Authors: Josh Sheppard & Pathfynder Inc Exploit Contact: ghost a t undervurse dot_com & josh a t pathfynder dot_io Exploit Technique: Remote CVE ID: CVE-2021-42952 1. Description A container escape vulnerability has been discovered in Zepl's Notebooks product. Upon lau

[FD] Zepl Notebook - Remote Code Execution

2022-02-16 Thread ghost
submission Exploit Authors: Josh Sheppard & Pathfynder Inc Exploit Contact: ghost a t undervurse dot_com & josh a t pathfynder dot_io Exploit Technique: Remote CVE ID: CVE-2021-42950 1. Description A remote code execution vulnerability has been discovered in Zepl's Notebooks produ

[FD] NEProfile - Host Header Injection

2020-08-25 Thread ghost
Exploit Title: NEProfile - Host Header Injection Date: 5/13/2020 Vendor Homepage: https://seczetta.com Software Link: https://seczetta.com/product/ne-profile Version: 3.3.11 Tested on: 3.3.11 Exploit Author: Josh Sheppard & Bryan Clements Exploit Contact: ghost () a t undervurse dot

[FD] NEProfile - Remote Code Execution

2020-07-14 Thread ghost
Exploit Title: NEProfile - Remote Code Execution Date: 5/13/2020 Vendor Homepage: https://seczetta.com Software Link: https://seczetta.com/product/ne-profile Version: 3.3.11 Tested on: 3.3.11 Exploit Author: Josh Sheppard Exploit Contact: ghost () a t undervurse dot_com Exploit Technique: Remote

[FD] OneShield - Policy Solutions - Dragon Framework Persistent XSS in Framework Textboxes

2019-05-04 Thread ghost
# Exploit Contact: ghost () a t undervurse dot_com # Exploit Technique: Remote # CVE: CVE-2019-11643 1. Description A persistent cross site scripting vulnerability has been found in the OneShield Policy (Dragon) framework. Remote adversaries can inject malicious JavaScript into textboxes decorated

[FD] OneShield - Policy Solutions - Dragon Framework Log Poisoning

2019-05-04 Thread ghost
# Exploit Title: Dragon - Log Poisoning # Date: 12/28/2018 # Vendor Homepage: https://oneshield.com # Software Link: https://oneshield.com/business-solutions/oneshield-pc-solutions/oneshield-policy/ # Version: 5.0, 5.1 # Tested on: 5.1 # Exploit Author: Josh Sheppard # Exploit Contact: ghost