RSS Feed

Proof of Concept

Die aktuelle Feed-Übersicht bündelt kuratierte Themen, relevante Quellfeeds und Live-Interessensgebiete in einem konsistenten, schnell nutzbaren Layout.

📰 IT NachrichtenDie Kult-Kamera der 2000er jetzt refurbished bei Back Market(17.09.2026 um 07:30 Uhr)
📰 IT NachrichtenGute Nachrichten für Android-Nutzer: Google liefert mehr Freiheit(17.09.2026 um 07:42 Uhr)
📰 IT NachrichtenDie Kult-Kamera der 2000er jetzt refurbished bei Back Market(17.09.2026 um 07:30 Uhr)
📰 IT NachrichtenGute Nachrichten für Android-Nutzer: Google liefert mehr Freiheit(17.09.2026 um 07:42 Uhr)
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence

⚠️ PoC

PoC packetstormsecurity.com
0
WordPress NextGEN Gallery Directory Read

This Metasploit module exploits an authenticated directory traversal vulnerability in WordPress Plugin "NextGEN Gallery" version 2.1.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
SAP BusinessObjects Web User Bruteforcer

This Metasploit module simply attempts to bruteforce SAP BusinessObjects users by using CmcApp.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Microsoft Windows Deployment Services Unattend Retrieval

This Metasploit module retrieves the client unattend file from Windows Deployment Services RPC service and parses out the stored credentials.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Memcached Stats Amplification Scanner

This Metasploit module can be used to discover Memcached servers which expose the unrestricted UDP port 11211.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
TFTP Brute Forcer

This Metasploit module uses a dictionary to brute force valid TFTP image names from a TFTP server.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
IpSwitch WhatsUp Gold TFTP Directory Traversal

This Metasploit modules exploits a directory traversal vulnerability in IpSwitch WhatsUp Golds TFTP service.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
NetDecision 4.2 TFTP Directory Traversal

This Metasploit modules exploits a directory traversal vulnerability in NetDecision 4.2 TFTP service.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Oracle XML DB SID Discovery Via Brute Force

This Metasploit module attempts to retrieve the sid from the Oracle XML DB httpd server, utilizing Pete Finnigans default oracle password list.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Oracle ISQLPlus SID Check

This Metasploit module attempts to bruteforce the SID on the Oracle application server iSQL*Plus login pages.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Oracle Account Discovery

This Metasploit module uses a list of well known default authentication credentials to discover easily guessed accounts.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Oracle TNS Listener SID Enumeration

This Metasploit module simply queries the TNS listener for the Oracle SID. With Oracle 9.2.0.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
URGENT/11 Scanner, Based On Detection Tool By Armis

This Metasploit module detects VxWorks and the IPnet IP stack, along with devices vulnerable to CVE-2019-12258.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Jetty WEB-INF File Disclosure

Jetty suffers from a vulnerability where certain encoded URIs and ambiguous paths can access protected files in the WEB-INF folder.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
GitLab Tags RSS Feed Email Disclosure

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read

This Metasploit module exploits CVE-2024-5806, an authentication bypass vulnerability in the MOVEit Transfer SFTP service.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
MongoDB Ops Manager Diagnostic Archive Sensitive Information Retriever

MongoDB Ops Manager Diagnostics Archive does not redact SAML SSL Pem Key File Password field (mms.saml.ssl.PEMKeyFilePassword) within app settings.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
ManageEngine DataSecurity Plus Xnode Enumeration

This Metasploit module exploits default admin credentials for the DataEngine Xnode server in DataSecurity Plus versions prior to 6.0.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Joomla com_contenthistory Error-Based SQL Injection

This Metasploit module exploits a SQL injection vulnerability in Joomla versions 3.2 through 3.4.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection

This Metasploit module exploits a SQL injection vulnerability found in vBulletin 5.x.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
IBM BigFix Relay Server Sites and Package Enum

This Metasploit module retrieves masthead, site, and available package information from IBM BigFix Relay Servers.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Advantech WebAccess 8.1 Post Authentication Credential Collector

This Metasploit module allows you to log into Advantech WebAccess 8.1, and collect all of the credentials.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
TeamTalk Gather Credentials

This Metasploit module retrieves user credentials from BearWare TeamTalk. Valid administrator credentials are required.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Rancher Authenticated API Credential Exposure

An issue was discovered in Rancher versions up to and including 2.5.15 and 2.6.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
BillQuick Web Suite txtID SQL Injection

This Metasploit module exploits a SQL injection vulnerability in BillQUick Web Suite prior to version 22.0.9.1. The application is .

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
ManageEngine ADAudit Plus Xnode Enumeration

This Metasploit module exploits default admin credentials for the DataEngine Xnode server in ADAudit Plus versions prior to 6.0.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Wordpress BookingPress bookingpress_front_get_category_services SQL Injection

The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied data in the total_service parameter of the…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
BMC / Numara Track-It! Domain Administrator and SQL Server User Password Disclosure

This Metasploit module exploits an unauthenticated configuration retrieval .NET remoting service in Numara / BMC Track-It! v9 to v11.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
HP ProCurve SNAC Domain Controller Credential Dumper

This Metasploit module will extract Domain Controller credentials from vulnerable installations of HP SNAC as distributed with HP ProCurve 4.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
HP Operations Manager Perfd Environment Scanner

This Metasploit module will enumerate the process list of a remote machine by abusing HP Operation Managers unauthenticated perfd daemon.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Dolibarr Gather Credentials via SQL Injection

This Metasploit module enables an authenticated user to collect the usernames and encrypted passwords of other users in the Dolibarr ERP/CRM via SQL…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Xymon Daemon Gather Information

This Metasploit module retrieves information from a Xymon daemon service (formerly Hobbit, based on Big Brother), including server configuration…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
WordPress All-in-One Migration Export

This Metasploit module allows you to export Wordpress data (such as the database, plugins, themes, uploaded files, etc) via the All-in-One Migration…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Mac OS X Safari file:// Redirection Sandbox Escape

Versions of Safari before 8.0.6, 7.1.6, and 6.2.6 are vulnerable to a "state management issue" that allows a browser window to be navigated to a…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
IBM Lotus Notes Sametime User Enumeration

This Metasploit module extracts usernames using the IBM Lotus Notes Sametime web interface using either a dictionary attack (which is preferred), or…

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
GitLab Authenticated File Read

GitLab version 16.0 contains a directory traversal for arbitrary file read as the gitlab-www user.

vor 2 Jahren 1 Min
Weiterlesen ↗
PoC packetstormsecurity.com
0
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump

This Metasploit module uses a blind SQL injection (CVE-2020-5724) affecting the Grandstream UCM62xx IP PBX to dump the users table.

vor 2 Jahren 1 Min
Weiterlesen ↗
Weitere 36 Beiträge laden
Seite 31 von 840 • Gesamt: 30.216 Artikel
2 Quellen 10
CVE-2022-44251 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUssd ussd command injection (EUVD-2022-47200)
2 Quellen 10
CVE-2022-44253 | TOTOLINK LR350 9.3.5u.6369_B20220309 setDiagnosisCfg via improper authentication (EUVD-2022-47202)
1 Quelle 8
Built a PPL-aware ALPC enumerator because standard handle duplication was leaving blind spots in the attack surface
1 Quelle 8
SindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)
1 Quelle 10
Heap-Buffer-Überlauf im Discord-Backend
1 Quelle 8
Looking for dedicated beginner ctf buddies
1 Quelle 22
BEING A GREAT HACKER
1 Quelle 8
0xCr0ssCrush - Windows BYOVD Ring 0 Exploit
1 Quelle 8
Centralizing scanner findings across multiple tools. anyone actually happy with their setup?
1 Quelle 8
I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table
1 Quelle 16
„Gerät finden“ auf Android kann sich jetzt auf Zuruf merken, wo ihr Gegenstände abgelegt habt
1 Quelle 10
From Bug to Schema: Exploring Error-Based SQL Injection on an Authenticating Portal
Threat Hunter Status-Update verfassen
Community Stream
News-Deck · Wischen zum Entscheiden 🔖 0 · ✕ 0

Karten werden geladen …

Rechts = merken · Links = überspringen · Hoch = lesen · Runter = zurück