Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   885

CVE-2024-26304

by iShagg - 09 May, 2024 - 01:18 AM
This post is by a banned member (iShagg) - Unhide
iShagg  
Registered
49
Posts
7
Threads
2 Years of service
#1
I know I just posted a CVE but, this one I tested...fruit don't get much lower to pick than this one!

Attack surface: 
  • ArubaOS 10.5.1.0 and below
  • ArubaOS 10.4.1.0 and below
  • ArubaOS 8.11.2.1 and below
  • ArubaOS 8.10.0.10 and below
  • SD-WAN 8.7.0.0-2.3.0.x
  • SD-WAN 8.6.0.4-2.2.x.x

Vulnerability: RCE
Description: There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

Exploit: https://github.com/Roud-Roud-Agency/CVE-...E-exploits

I'm serious, this one is just plug and play guys! Enjoy :)
This post is by a banned member (Zed) - Unhide
Zed  
Registered
1.163
Posts
192
Threads
5 Years of service
#2
@iShagg what is your telegram ?
UpgraderCx offers prepaid upgrades for a wide range of online services, including:Spotify Premium, YouTube Premium, Crunchyroll Fan and Mega Fan, Disney+ and much more..
Website : https:upgradercx.com

Telegram : https://t.me/upgradercx
Discord Server : https://discord.gg/upgradercx
TrustPilot reviews : https://www.trustpilot.com/review/upgradercx.com
This post is by a banned member (iShagg) - Unhide
iShagg  
Registered
49
Posts
7
Threads
2 Years of service
#3
I don't do telegram, I'm sorry  Feelssadman
This post is by a banned member (iShagg) - Unhide
iShagg  
Registered
49
Posts
7
Threads
2 Years of service
Bumped #4
This is a bump
This post is by a banned member (iShagg) - Unhide
iShagg  
Registered
49
Posts
7
Threads
2 Years of service
Bumped #5
This is a bump
This post is by a banned member (topstresser) - Unhide
229
Posts
6
Threads
2 Years of service
#6
Cool, but CVE of some newer wordpress version would be a lot of more useful. Keep this up.
This post is by a banned member (iShagg) - Unhide
iShagg  
Registered
49
Posts
7
Threads
2 Years of service
Bumped #7
(This post was last modified: 21 May, 2024 - 04:59 AM by iShagg.)
This is a bump

(16 May, 2024 - 09:51 AM)topstresser Wrote: Show More
Cool, but CVE of some newer wordpress version would be a lot of more useful. Keep this up.

Well, this exploit i linked also covers CVE-2024-26305, CVE-2024-33511, CVE-2024-33512 and also gives the option to exploit multiple urls...wouldn't take a lot, a shodan api and a simple parser to make an autopwn script. I bet I could do it in node and get real fancy with it....someone with enough capital could get even more fancy with it

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)