h00die-gr3y

55 exploits Active since Sep 2014
CVE-2022-26318 METASPLOIT CRITICAL ruby WORKING POC
WatchGuard XTM Firebox Unauthenticated Remote Command Execution
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
CVSS 9.8
CVE-2024-2054 METASPLOIT CRITICAL ruby WORKING POC
Artica-Proxy - Unauthenticated Remote Code Execution via PHP Deserialization
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
CVSS 9.8
CVE-2022-33891 METASPLOIT HIGH ruby WORKING POC
Apache Spark UI - Privilege Escalation
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.
CVSS 8.8
CVE-2022-24989 METASPLOIT CRITICAL ruby WORKING POC
TerraMaster TOS < 4.2.31 - Unauthenticated Remote Code Execution via api.php Raid Creation
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials from CVE-2022-24990 exploitation can be used.
CVSS 9.8
CVE-2020-28188 METASPLOIT CRITICAL ruby WORKING POC
TerraMaster TOS <= 4.2.06 - Unauthenticated Remote Code Execution via Event Parameter
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
CVSS 9.8