Mac OS X

Evological EvoCam Remote Buffer Overflow Exploit

The vulnerability is caused due to a boundary error in the included web server when processing HTTP requests. This can be exploited to cause a stack-based buffer overflow via an overly long GET request.

Mac OS X CUPS lppasswd Local Privilege Escalation Exploit

This module exploits a format string vulnerability in CUPS lppasswd in Apple Mac OS X 10.5.6 that allows local users to get code execution with elevated privileges.

Remote Exploits Service Package Update

This package specify the service to be attacked, taking the info from services.py.

OpenX Remote Code Execution Exploit

The vulnerability is caused due to the banner-edit.php script allowing the upload of files with arbitrary extensions to a folder inside the webroot. This can be exploited to e.g. execute arbitrary PHP code by uploading a specially crafted PHP script that contains the GIF magic number.

ISC BIND Dynamic Update Message DoS Exploit Update

A vulnerability has been identified in ISC BIND, which could be exploited by remote attackers to cause a denial of service.

Sudoedit Privilege Escalation Exploit

Exploits a missing verification of the path in the command "sudoedit", provided by the sudo package. This can be exploited to e.g. execute any command as root including a shell, allowing an unprivileged process to elevate privileges to root. This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations.

Apple iTunes PLS File Stack Overflow Exploit

Apple iTunes is prone to a buffer-overflow vulnerability because the software fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

PhpMyAdmin Unserialize Remote Code Execution Exploit

phpMyAdmin is vulnerable to a remote code execution due the use of the unserialize method on user supplied data. This data is written in the config file and is accessible from the internet by default.

DAZ Studio Script Exploit

This module abuses the scripting functionality in DAZ Studio to trigger remote code execution via a DAZ Script file.

Autodesk Maya ScriptNode Exploit

This module abuses the scripting functionality in Autodesk Maya to trigger remote code execution via a specially crafted file.