Burninator Sec

This blog is about the educational (and sometimes entertainment) value of simple hacks. For active vulnerabilities, real names are concealed.

Tuesday, April 13, 2021

CVE-2020-29592 and CVE-2020-29593 - Orchard CMS Unrestricted File Upload and XSS

›
  Note: This is fixed in Orchard 1.10, this post is about Orchard 1.8.1.0. CVE-2929-29592 - Unrestricted File Upload via Media Folder and Ti...

RCE Using Recaf: an Awesome Java Decompiler/Recompiler

›
Recaf is super slick for reverse engineering and editing Java, I used it for arbitrary command injection (for RCE running as root!) last wee...

Hash Cracking with Rental AI GPUs

›
I've been doing a lot with fast.ai lately and really enjoying it. The worst part about AI is how long it takes to train a model, realize...

CVE-2020-26885 - XSS in 2SXC

›
Reflected XSS via the sxcver parameter on the /DesktopModles/tosic_sexycontent/dist/dnn/ui.html page by using the payload:   "><I...
Monday, April 12, 2021

CVE-2021-3163 - Stored XSS Slab Quill JS

›
 XSS in the WYSIWYG HTML editor by abusing the image tag.   For example, in the POST request when adding a comment, add this payload to the ...
6 comments:
Tuesday, April 6, 2021

Bamboozle D 3 f en d e r Effortlessly (BDE) - File Lock on Shell Code

›
Still confirming this is working the way I intend it, updates and detailed POC to follow... I found RCE in a web application, and place a w...
Sunday, November 29, 2020

Palo Alto Networks - WAF Bypass for Webshell

›
I originally found/reported to Palo Alto in 2018. You can use the default Kali Linux aspx webshell to get RCE on a server protected by Palo ...
‹
›
Home
View web version
Powered by Blogger.