This archive contains all of the 106 exploits added to Packet Storm in February, 2024.
fbeeba3e5095c48fa40ffef93379125b9600aa791763df12b1e8c38c10bdd59a
Backdoor.Win32.Agent.amt malware suffers from bypass and code execution vulnerabilities.
b6b18194f2e689d34f31467983fac3c6ef3ca487f56d307bb7a3aba5b961cffd
Backdoor.Win32.Jeemp.c malware suffers from a hardcoded credential vulnerability.
5e4ddaa4fb20fd54762a11e5e3b4f3336161f26cd683100a9b9009e19ba332e0
WordPress IDonate Blood Request Management System plugin versions 1.8.1 and below suffer from a persistent cross site scripting vulnerability.
deb442f6accbca69dc829364f209cc07083ae35484b8d9dbcf49d6fb5acec053
In the tgnet library used in Telegram messenger for Android, there is a use-after-free vulnerability in Connection::onReceivedData that can be triggered remotely.
bca6a67a76c752f1ecdcd8907312e1eb9daa4808f56fcf845f91420c4d98f5d4
This is a key derivation exploit for Saflokk System 6000.
77fb2e53166bf30d0f69ef4d47cfe5bbebe8ef4c1ea6e0b05a88615b3c1fde28
Blood Bank version 1.0 suffers from multiple remote SQL injection vulnerabilities. Original discovery of SQL injection in this version is attributed to Nitin Sharma in October of 2021.
b80ea9dc4dcabb3799a9c6566f8928f2eaa8d06049d1d71965c70f4f1c6af8b7
WordPress WP Fastest Cache plugin version 1.2.2 suffers from an unauthenticated remote SQL injection vulnerability.
38c4ccc413d62f200211fb17cb0cd093832fd5b828e079e5fdf40dfcd8083574
WordPress Admin Bar and Dashboard Access Control plugin version 1.28 suffers from a persistent cross site scripting vulnerability.
b4ad5f139e9d3b2516b87a994569e0646ffb052a5990072054404ca117aece0b
Hospital Management System version 1.0 suffers from insecure direct object reference and account takeover vulnerabilities.
be19d62054d99ae7a13a56bfe14d696f9386cb9b1076c31c5d2ce818f0bec232
Hospital Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
ee80dd4b7307acb7e78dc9fe5a4441a93e60abc361a7fa9ad6121fdf7e97628c
Hospital Management System version 1.0 suffers from a remote SQL injection vulnerability.
d44a649c2c912867d906854a7f620e0dc403f37dffff37c544bc1619094d5b96
Executables created with perl2exe versions 30.10C and below suffer from an arbitrary code execution vulnerability.
4cecfc183baf33a9505c1e103e36e7ae9acc23ba7f3fc80294c995ac275e79b0
Automatic-Systems SOC FL9600 FastLine version V06 has hardcoded credentials for super admin functionality.
8d39714181692d67f93a9e46f5f0953216b012889a3b7ebbe7fa9cd7bf60bd0d
Automatic-Systems SOC FL9600 FastLine version V06 suffers from a directory traversal vulnerability.
e43491c92de6a6e95e9bcf00c8f526235bfba3e6efc005c1ff1ac8382b3fa1ae
This Metasploit module exploits a broken access control vulnerability in Atlassian Confluence servers leading to an authentication bypass. A specially crafted request can be create new admin account without authentication on the target Atlassian server.
c9933148dbb3513e341045ef4dcef5999b02882361749da2c6cd6cfe8c0471bc
Moodle version 4.3 suffers from an insecure direct object reference vulnerability.
0485561a16603707f6cfa13e517e05e872b10a48a6b02c4acd2dd562d2182284
WordPress Canto versions prior to 3.0.5 suffer from remote file inclusion and shell upload vulnerabilities.
a59ad7feb866d8c5d65a87422165e0d5c276bf4da7b8e83a100a1933f7afdf64
WordPress Comments Like Dislike plugin versions 1.2.0 and below suffer from a missing capability check on the restore_settings function that allows an attacker to reset the plugin's settings.
30694c0d87c0279433026fa6057e69b38edd9bdf49da277bc82125dd688bd97e
SuperStoreFinder versions 3.7 and below suffer from cross site request forgery, remote command execution, and remote SQL injection vulnerabilities.
8a5a27ee2cdba842a87bb56778f36fe0e630257be6595b634453cc2afcaf8a8c
Simple Inventory Management System version 1.0 suffers from a remote SQL injection vulnerability.
8e51d27e9d209102d0cc21f4fcd8ca293e548ced1856940a8a497960d3d17967
Flashcard Quiz App version 1.0 suffers from a remote SQL injection vulnerability.
2d19f05f546a17fd7531fb2d8505ca2f52f76ae282a5f46a1b55c2ced76fd1ef
FAQ Management System version 1.0 suffers from a remote SQL injection vulnerability.
2ea51098a949106e71b766b144109b1be9da517c51665344c9ebb17028a158a4
Backdoor.Win32.AutoSpy.10 malware suffers from a remote command execution vulnerability.
01433d0ad222e5da0927202b151b19c29afd6ce5f59f4e0b3302a97ed91a29bb
Tosibox Key Service versions 3.3.0 and below suffer from an unquoted search path issue impacting the service Tosibox Key Service for Windows. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
7820f9f7d9af81913956c26707d4acc215ad499c129864227adf8ac1f2345e47