-
PHP Files ≈ Packet Storm
Dec 2, 2024 | 18:33 pm
ABB Cylon Aspect version 3.08.00 suffers from a vulnerability in the fileSystemUpdate.php endpoint of the ABB BEMS controller due to improper handling of uploaded files. The endpoint lacks restrictions on file size and type, allowing attackers to upload excessively large[…]
Read more...
-
PHP Files ≈ Packet Storm
Nov 27, 2024 | 15:05 pm
ABB Cylon Aspect version 3.08.01 suffers from an unauthenticated configuration download vulnerability. This can be exploited to download the CSV DB that contains the configuration mappings information via the VMobileImportExportServlet by directly calling the vstatConfigurationDownload.php script.
Read more...
-
PHP Files ≈ Packet Storm
Nov 27, 2024 | 15:04 pm
Debian Linux Security Advisory 5819-1 - Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, CLRF injection or information disclosure.
Read more...
-
PHP Files ≈ Packet Storm
Nov 22, 2024 | 15:42 pm
This Metasploit module exploits an improper authorization vulnerability in ProjectSend versions r1295 through r1605. The vulnerability allows an unauthenticated attacker to obtain remote code execution by enabling user registration, disabling the whitelist of allowed file extensions, and uploading a malicious[…]
Read more...
-
PHP Files ≈ Packet Storm
Nov 18, 2024 | 15:08 pm
Debian Linux Security Advisory 5813-1 - Moritz Rauch discovered that the Symfony PHP framework implemented persisted remember-me cookies incorrectly, which could result in authentication bypass.
Read more...
-
PHP Files ≈ Packet Storm
Nov 15, 2024 | 13:25 pm
Ubuntu Security Notice 7049-2 - USN-7049-1 fixed vulnerabilities in PHP. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. It was discovered that PHP incorrectly handled parsing multipart form data. A remote attacker could possibly[…]
Read more...
-
PHP Files ≈ Packet Storm
Nov 14, 2024 | 15:42 pm
Proof of concept remote code execution exploit for PHP-CGI that affects versions 8.1 before 8.1.29, 8.2 before 8.2.20, and 8.3 before 8.3.8.
Read more...
-
PHP Files ≈ Packet Storm
Nov 14, 2024 | 15:37 pm
This is a bash script that is a vulnerability checker for CVE-2024-4577 designed to scan multiple domains for an argument injection vulnerability in PHP-CGI. This tool allows security researchers and system administrators to quickly assess whether their systems or a[…]
Read more...
-
PHP Files ≈ Packet Storm
Nov 12, 2024 | 15:10 pm
Debian Linux Security Advisory 5809-1 - Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to privilege escalation, information disclosure, incorrect validation or an open redirect.
Read more...
-
PHP Files ≈ Packet Storm
Nov 1, 2024 | 15:08 pm
ABB Cylon Aspect version 3.08.01 has a vulnerability in caldavInstall.php, caldavInstallAgendav.php, and caldavUpload.php files, where the presence of an EXPERTMODE parameter activates a badassMode feature. This mode allows an unauthenticated attacker to bypass MD5 checksum validation during file uploads. By[…]
Read more...
-
PHP Files ≈ Packet Storm
Nov 1, 2024 | 14:54 pm
SmartAgent version 1.1.0 suffers from an unauthenticated remote code execution vulnerability in youtubeInfo.php.
Read more...
-
PHP Files ≈ Packet Storm
Oct 30, 2024 | 15:34 pm
ABB Cylon Aspect version 3.08.01 is vulnerable to username enumeration in the jsonProxy.php endpoint. An unauthenticated attacker can interact with the UserManager servlet to enumerate valid usernames on the system. Since jsonProxy.php proxies requests to internal services without requiring authentication,[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 30, 2024 | 15:32 pm
ABB Cylon Aspect version 3.08.01 is vulnerable to unauthorized information disclosure in the jsonProxy.php endpoint. An unauthenticated attacker can retrieve sensitive system information, including system time, uptime, memory usage, and network load statistics. The jsonProxy.php endpoint proxies these requests to[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 30, 2024 | 15:31 pm
ABB Cylon Aspect version 3.08.01 is vulnerable to unauthorized SSH service configuration changes via the jsonProxy.php endpoint. An unauthenticated attacker can enable or disable the SSH service on the server by accessing the FTControlServlet with the sshenable parameter. The jsonProxy.php[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 30, 2024 | 15:28 pm
ABB Cylon Aspect version 3.08.01 is vulnerable to an unauthenticated denial of service attack in the jsonProxy.php endpoint. An attacker can remotely restart the main Java server by accessing the FTControlServlet with the restart parameter. The endpoint proxies requests to[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 30, 2024 | 15:26 pm
ABB Cylon Aspect version 3.08.01 is vulnerable to an unauthorized project file disclosure in jsonProxy.php. An unauthenticated remote attacker can issue a GET request abusing the DownloadProject servlet to download sensitive project files. The jsonProxy.php script bypasses authentication by proxying[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 30, 2024 | 15:25 pm
ABB Cylon Aspect version 3.08.01 is vulnerable to remote, arbitrary servlet inclusion. The jsonProxy.php endpoint allows unauthenticated remote attackers to access internal services by proxying requests to localhost. This results in an authentication bypass, enabling attackers to interact with multiple[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 24, 2024 | 13:31 pm
A cross site scripting vulnerability in pfsense version 2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
Read more...
-
PHP Files ≈ Packet Storm
Oct 22, 2024 | 15:49 pm
ABB Cylon Aspect version 3.08.01 suffers from an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the directory HTTP POST parameter called by the persistenceManagerAjax.php script.
Read more...
-
PHP Files ≈ Packet Storm
Oct 21, 2024 | 12:40 pm
Helper is an enumerator written in PHP that helps identify directories on webservers that could be targets for things like cross site scripting, local file inclusion, remote shell upload, and remote SQL injection vulnerabilities.
Read more...
-
PHP Files ≈ Packet Storm
Oct 18, 2024 | 14:25 pm
This Metasploit module uses a combination of an arbitrary file read (CVE-2024-34102) and a buffer overflow in glibc (CVE-2024-2961). It allows for unauthenticated remote code execution on various versions of Magento and Adobe Commerce (and earlier versions if the PHP[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 18, 2024 | 14:22 pm
ABB Cylon Aspect version 3.08.01 suffers from an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the file HTTP POST parameter called by the databaseFileDelete.php script.
Read more...
-
PHP Files ≈ Packet Storm
Oct 17, 2024 | 13:46 pm
ABB Cylon Aspect version 3.08.01 allows an unauthenticated attacker to perform network operations such as ping, traceroute, or nslookup on arbitrary hosts or IPs by sending a crafted GET request to networkDiagAjax.php. This could be exploited to interact with or[…]
Read more...
-
PHP Files ≈ Packet Storm
Oct 16, 2024 | 14:31 pm
ABB Cylon Aspect version 3.08.01 suffers from an unauthenticated configuration download vulnerability. This can be exploited to download the SQLite DB that contains the configuration mappings information via the FTControlServlet by directly calling the mapConfigurationDownload.php script.
Read more...
-
PHP Files ≈ Packet Storm
Oct 15, 2024 | 14:19 pm
ABB Cylon Aspect version 3.08.00 suffers from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the country, state, locality, organization, and hostname HTTP POST parameters called by the sslCertAjax.php script.
Read more...