jsp exploits
Page 1 of 41 exploits
Title Author Platform Source Description Date
Openfire <= 3.6.0a Admin Console Authentication Bypass metasploit jsp exploit-db.com This file is part of the Metasploit Framework and may be subject to redistribution and commercial restrictions. Please see the Metasploit Framework web site for more information on licensing and terms of use. http://metasploit.com/framework/ require 'msf/core' require 'rex/z June 28
ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet Unauthenticated Remote Directory Traversal Vulnerability rgod jsp exploit-db.com ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet Unauthenticated Remote Directory Traversal Database Backup / auth-conf.xml Disclosure Exploit product homepage: http://www.manageengine.com/products/device-expert/ file tested: ManageEngine_DeviceExpert.exe tested against: Micros March 19, 2012
Stoneware WebNetwork6 Multiple Vulnerabilities Jacob Holcomb jsp exploit-db.com Stoneware WebNetwork6 Vulnerability Assessment Conducted by: * Leland Public Schools (Stoneware Customer) * Jacob Holcomb (Network Engineer for LPS) Conducted for: * Leland Public Schools (Purchaser of WebNetwork product. Test was to assure cloud security) * Stoneware INC. (Discovered Zer January 24, 2012
Cloupia End-to-end FlexPod Management Directory Traversal Chris Rock jsp exploit-db.com *Cloupia End-to-end FlexPod Management - Directory Traversal Vulnerability*** *Advisory Information* Advisory ID: KUSTODIAN-2011-011 Date published: Jan 13, 2011 *Vulnerability Information* Class: Directory Traversal Remotely Exploitable: Yes Locally Exploitable: Yes *Softwar January 15, 2012
Barracuda Control Center 620 Multiple Vulnerabilities Vulnerability-Lab jsp exploit-db.com Title: Barracuda Control Center 620 - Multiple Web Vulnerabilities Date: = 2011-12-21 References: = http://www.vulnerability-lab.com/get_content.php?id=32 VL-ID: = 32 Introduction: = Barracuda Networks - Worldwide leader in email and January 6, 2012
Barracuda Control Center 620 - Multiple Web Vulnerabilities Vulnerability-Lab jsp exploit-db.com Title: Barracuda Control Center 620 - Multiple Web Vulnerabilities Date: = 2011-12-21 References: = http://www.vulnerability-lab.com/get_content.php?id=32 VL-ID: = 32 Introduction: = Barracuda Networks - Worldwide leader in email and December 21, 2011
Java Applet Rhino Script Engine Remote Code Execution metasploit jsp exploit-db.com This file is part of the Metasploit Framework and may be subject to redistribution and commercial restrictions. Please see the Metasploit Framework web site for more information on licensing and terms of use. http://metasploit.com/framework/ require 'msf/core' require 'rex' November 30, 2011
IBM Lotus Domino Server Controller Authentication Bypass Vulnerability Alexey Sintsov jsp exploit-db.com Exploit Title: IBM Lotus Domino Controller auth. bypass Date:30/11/2011 Author: Alexey Sintsov Software Link: http://www.ibm.com/ Version:8.5.3/8.5.2 FP3 (0day)  Tested on: Windows 7 / Windows 2008 CVE : CVE-2011-1519 Application: IBM Lotus Domino Controller Versions Affect November 30, 2011
JBoss, JMX Console, misconfigured DeploymentScanner y0ug jsp exploit-db.com !/usr/bin/perl Exploit Title: JBoss, JMX Console, misconfigured DeploymentScanner Date: Oct 3 2011 Author: y0ug codsec.com Version: Tested on: Linux CVE : CVE-2010-0738 POC against misconfigured JBoss JMX Console It use the addUrl method in DeploymentScanner module October 3, 2011
Multiple Vulnerability in Omnidocs Sohil Garg jsp exploit-db.com -------------------------------------------------------------------- Exploit Title: Multiple Vulnerability in "Omnidocs" Date: 24 Sep 2011 Author: Sohil Garg Software Link: http://www.newgensoft.com/omnidocs.asp Version: All Tested on: Apache-Coyote/1.1 CVE : CVE-2011-3645 � - September 27, 2011
Nortel Contact Recording Centralized Archive 6.5.1 SQL Injection Exploit rgod jsp exploit-db.com September 15, 2011
ManageEngine ServiceDesk Plus 8.0 Multiple Stored XSS Vulnerabilities LiquidWorm jsp exploit-db.com ManageEngine ServiceDesk Plus 8.0 Multiple Stored XSS Vulnerabilities Vendor: Zoho Corporation Pvt. Ltd. Product web page: http://www.manageengine.com Affected version: 8.0.0 Build 8013 (Enterprise) Summary: ServiceDesk Plus integrates your help desk requests and assets to help you manage August 23, 2011
Sun/Oracle GlassFish Server Authenticated Code Execution metasploit jsp exploit-db.com $Id: glassfish_deployer.rb 13485 2011-08-04 17:36:01Z hdm $ This file is part of the Metasploit Framework and may be subject to redistribution and commercial restrictions. Please see the Metasploit Framework web site for more information on licensing and terms of use. htt August 5, 2011
CA Arcserve D2D GWT RPC Credential Information Disclosure metasploit jsp exploit-db.com $Id: ca_arcserve_rpc_authbypass.rb 13467 2011-08-01 21:20:29Z sinn3r $ This file is part of the Metasploit Framework and may be subject to redistribution and commercial restrictions. Please see the Metasploit Framework web site for more information on licensing and terms of August 1, 2011
ManageEngine ServiceDesk Plus 8.0 Build 8013 Multiple XSS Vulnerabilities Narendra Shinde jsp exploit-db.com = Secur-I Research Group Security Advisory [ SV-2011-003] = Title: ManageEngine ServiceDesk Plus 8.0 Build 8013 Multiple Persistence Cross Site Scripting Vul July 29, 2011