Open Source

Untuk seluruh software yang bersifat Open Source tidak akan tenggelam oleh waktu dikarenakan banyak yang mendukung program tersebut dan software tersebut tidak kalah bersaing dengan software berbayar lainnya.

Rabu, 05 April 2017

CSRF / Privilege Escalation (Manipulation of Role Agent to Admin) on Faveo version Community 1.9.3

Exploit Title: CSRF / Privilege Escalation (Manipulation of Role Agent to Admin) on Faveo version Community 1.9.3 Date: 05-April-2017 Exploit Author: @rungga_reksya, @yokoacc, @AdyWikradinata, @dickysofficial, @dvnrcy Vendor Homepage: http://www.faveohelpdesk.com/ Software Link: https://codeload.github.com/ladybirdweb/faveo-helpdesk/zip/v1.9.3 Version: Community 1.9.3 Tested on: Windows Server 2012 Datacenter Evaluation CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L...

Multiple CSRF / Code Execution Vulnerability on HelpDEZK 1.1.1

# Exploit Title: Multiple CSRF / Code Execution Vulnerability on HelpDEZK 1.1.1# Date: 05-April-2017# Exploit Author: @rungga_reksya, @yokoacc, @AdyWikradinata, @dickysofficial, @dvnrcy# Vendor Homepage: http://www.helpdezk.org/# Software Link: https://codeload.github.com/albandes/helpdezk/zip/v1.1.1# Version: 1.1.1# Tested on: Windows Server 2012 Datacenter Evaluation# CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 - CRITICAL)I. Background:HelpDEZk...

Minggu, 02 April 2017

Remote File Upload Vulnerability in File Manager Pixie 1.0.4 With Low Privilege

# Exploit Title: Remote File Upload Vulnerability in File Manager Pixie 1.0.4 With Low Privilege# Google Dork: no# Date: 02-April-2017# Exploit Author: @rungga_reksya, @dvnrcy, @dickysofficial# Vendor Homepage: http://www.getpixie.co.uk# Software Link: https://us.softpedia-secure-download.com/dl/44791fdde14260bc7a8d08df65bcd048/58db4b5c/700044699/webscripts/php/pixie_v1.04.zip# Version: 1.0.4# CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (7.5 - HIGH) #...