Ransomware Simulation Enhancement - Rename encrypted files |
This update adds a new parameter to the "Ransomware Simulation" module: "RENAME FILES"; if set to TRUE, encrypted files will also be renamed by adding the .1mp4ct extension to them. |
May 27, 2022 |
NOCVE-9999-175115 |
|
Post Exploitation |
Impact |
Microsoft Windows Point-to-Point Tunneling Protocol DoS |
A denial of service vulnerability exists in Point-to-Point Tunneling Protocol service when an unauthenticated attacker connects to the target system and sends specially crafted requests. |
May 24, 2022 |
CVE-2022-23253 |
Windows |
Denial of Service / Remote |
Impact |
Ransomware Simulation |
This update adds a couple modules to simulate a ransomware attack in a previously exploited host. "Ransomware Simulation" to run the simulated ransomware attack. "Files Decryption after Ransomware Simulation" to decrypt previously encrypted files. |
May 20, 2022 |
NOCVE-9999-175115 |
|
Post Exploitation |
Impact |
F5 BIG-IP iControl REST Authentication Bypass Vulnerability Remote Code Execution Exploit |
An athentication bypass present in iControl REST of F5 BIG-IP allows unauthenticated remote attackers to execute OS commands as root. |
May 10, 2022 |
CVE-2022-1388 |
Linux |
Exploits / OS Command Injection / Known Vulnerabilities |
Impact |
VMware Workspace ONE Access Server-side Template Injection Remote Code Execution Exploit |
The customError.ftl filter in VMware Workspace ONE Access allows remote attackers to achieve remote code execution via server-side template injection. |
May 10, 2022 |
CVE-2022-22954 |
Linux |
Exploits / OS Command Injection / Known Vulnerabilities |
Impact |
Spring Framework Spring4Shell Remote Code Execution Exploit |
An unsafe data binding used to populate an object from request parameters (either query parameters or form data) to set a Tomcat specific ClassLoader in Spring MVC and Spring WebFlux applications allows unauthenticated attackers to upload and execute a JSP file in the Tomcat virtual file system webapps directory. |
May 4, 2022 |
CVE-2022-22965 |
Linux |
Exploits / OS Command Injection / Known Vulnerabilities |
Impact |
Zenario CVE-2021-42171 Auth Arbitrary File Upload |
CVE-2021-42171 Zenario 9.0.54156 Arbitrary File Upload |
April 30, 2022 |
|
Windows, Linux |
Exploits / Remote Code Execution |
SCADAPRO |
Spring4Shell |
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. |
April 30, 2022 |
|
|
Exploits / Remote Code Execution |
SCADAPRO |
ScriptCase 9.7.016 - Arbitrary File Deletion |
ScriptCase 9.7.016 is vulnerable for Arbitrary File Deletion from admin's account Authorized attacker can delete any file in the system |
April 30, 2022 |
|
|
Exploits / Remote |
SCADAPRO |
CouchDB CVE-2022-24706 Remote Code Execution |
CouchDB 3.2.1 CVE-2022-24706 Remote Code Execution |
April 30, 2022 |
|
Windows, Linux |
Exploits / Remote Code Execution |
SCADAPRO |
XISOM X-Scada Viewer Directory Traversal Vulnerability 0day |
This module exploits a directory traversal vulnerability in XISOM X-Scada Viewer Web Server |
April 30, 2022 |
|
Windows |
Exploits / Remote |
SCADA |
PostgreSQL CVE-2019-9193 Remote Code Execution |
CVE-2019-9193 PostgreSQL Command Execution |
April 30, 2022 |
|
Linux, Windows |
Exploits / Remote Code Execution |
SCADA |
Moodle CVE-2022-0983 Auth SQL Injection |
Moodle 3.11.5 Authenticated SQL Injection |
April 30, 2022 |
|
|
Exploits / Remote |
SCADA |
Oracle Access Manager OpenssoEngineController Deserialization Vulnerability Remote Code Execution Exploit |
A deserialization vulnerability present in the OpenssoEngineController component of Oracle Access Manager allows a unauthenticated attacker with network access via HTTP to execute system commands. |
April 25, 2022 |
CVE-2021-35587 |
Windows, Linux |
Exploits / Remote Code Execution |
Impact |
Linux Kernel watch_queue Local Privilege Escalation Exploit |
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel's watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system. |
April 19, 2022 |
CVE-2022-0995 |
Linux |
Exploits / Local |
Impact |
Apache APISIX batch-requests Remote Code Execution Exploit (CVE-2022-24112) |
This module exploits a vulnerability in Apache APISIX batch requests plugin to perform a remote code execution. |
April 7, 2022 |
CVE-2022-24112 |
Linux |
Exploits / Remote Code Execution |
Impact |
Webmin CVE-2022-0824 |
CVE-2022-0824 Webmin 1.984 Remote Code Exection |
March 30, 2022 |
|
Linux |
Exploits / Remote Code Execution |
SCADAPRO |
CVE-2022-0332 |
Moodle 3.11-3.11.4 Authenticated SQL Injection |
March 30, 2022 |
|
|
Exploits / Remote |
SCADAPRO |
Yokogawa Centum CS3000 R3.08.50 Denial of Service |
This module Denial of Service in Yokogawa CS3000 by sending a malformed packet to the 20010/UDP port. |
March 30, 2022 |
CVE-2014-3888 |
Linux |
Denial of Service / Remote |
SCADA |
aaPanel 6.8.21 Authenticated Directory Traversal |
aaPanel 6.8.21 Authenticated Directory Traversal |
March 30, 2022 |
|
Linux |
Exploits / Remote File Disclosure |
SCADA |
Veeam Backup and Replication ExecuteUploadManagerPerformUpload Remote Code Execution Exploit |
An authentication bypass in Veeam.Backup.ServiceLib.CForeignInvokerNegotiateAuthenticator.Authenticate and a file upload present in ExecuteUploadManagerPerformUpload allows an unauthenticated attacker to execute system commands with the privileges of the "IIS Worker Process" process (NT AUTHORITY\\NETWORK SERVICE) |
March 23, 2022 |
CVE-2022-26501 |
Windows |
Exploits / Remote Code Execution |
Impact |
Microsoft Windows HTTP Stack DoS |
This bug could allow an attacker to gain code execution on an affected system by sending specially crafted packets to a system utilizing the HTTP Protocol Stack (http.sys) to process packets. No user interaction, no privileges required, and an elevated service add up to a wormable bug. And while this is definitely more server-centric, remember that Windows clients can also run http.sys, so all affected versions are affected by this bug. Test and deploy this patch quickly. |
March 18, 2022 |
CVE-2022-21907 |
Windows |
Denial of Service / Remote |
Impact |
Apache James Log4shell Remote Code Execution Vulnerability Exploit |
Description: JNDI features used in configuration, log messages, and parameters present in Apache Log4j2 do not protect against attacker controlled LDAP and other JNDI related endpoints. This library, used by Apache James, allows unauthenticated attackers to execute system commands. |
March 17, 2022 |
CVE-2021-44228 |
Linux, Windows |
Exploits / Remote |
Impact |
Microsoft Windows Administrator UAC Elevation Bypass Update v2 |
This update improves the module to bypass UAC by adding support for Windows 11. |
March 15, 2022 |
NOCVE-9999-64489 |
Windows |
Exploits / Local |
Impact |
Linux Kernel Dirty Pipe Local Privilege Escalation Exploit |
Improper initialization of the flags member of the pipe buffer structure in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel, could allow an unprivileged local user to write to pages in the page cache backed by read-only files and escalate privileges on the system. |
March 14, 2022 |
CVE-2022-0847 |
Linux |
Exploits / Local |
Impact |