Agora Exploitation Pack for CANVAS. Due to the product continuous update in nature, so we prepare this post for those who interest to know what is include inside. Latest update will be show on the top, while older update will be auto show below. This post will keep update and the post date will follow the latest date, so it will show one post date, rather than multiple post for hassle free reading in one post. This post is about CANVAS Exploitation Pack (CEP) Agora, it need to be use with CANVAS Exploitation Testing Framework. Feel free to contact E-SPIN for product and related matter.
Agora Exploitation Pack for CANVAS Product Overview
The Agora Pack was released by GLEG research team in the beginning of 2008.
The Pack is a successor of Argeniss ultimate 0day pack, which was developed since 2006 and acquired by GLEG in 2008.
More than 50 database modules contained in Argeniss pack were redesigned and included to Agora.
The Pack is continuously enhanced and now contains more than 550 modules.
To keep exploit pack always actual, we provide monthly updates with 3-7 modules for most valuable fresh vulns.
Current updates are focused on Web related software and a value add: defense bypass + database modules.
The Agora Pack features:
- Fresh & unpatched stuff each month – 3-7 modules
- Modules for latest mainstream WEB related software
- Value add: Modules to defeat the defense, hack the database etc.
- New attack techniques
2019-Aug-10 2.82 ver. of Agora contains following addition:
2019-Jul-23 2.90 ver. of Agora contains 2 modules. List:
– most of windows platforms Remote Desktop Denial of Service. public.
2019-Jun-3 2.89 ver. of Agora contains 3 modules. List:
2019-May-21 2.88 ver. of Agora contains 4 modules. List:
– MarcomCentral FusionPro VDP Creator 9.x Directory Traversal. CVE-2019-7751
2019-Jan-27 2.85 ver. of Agora contains 4 modules. List:
2018-Nov-26 2.83 Agora:
– ServersCheck MonitoringDoS [1day] – Easewe FTP, Touch22 Software ActiveX Controls – 3 modules [1day]
2018-Oct-25 2.82 Agora:
– Navigate CMS 8.2 RCE. CVE 2018-17552, CVE 2018-17553
– Traq 3.7.1 SQL Injection. public
– Cybrotech CyBroHttpServer Directory Traversal. [1day] – Argus Surveillance DVR 126.96.36.199 devices info leak. CVE-2018-15745.
2018-Sep-26 2.81 Agora :
– Socomec UPS and low voltage monitoring software. LocalView Info Disclosure +
RemoteView PRO AFU RCE. two [1day] modules
– Solarwinds Kiwi Syslog Server Denial of Service [1day] – Dotclear 2.9.1 Shell Upload Vulnerability. [public]
2018-Aug-29 2.80 Agora contains 4 [1day] modules:
– Antamedia HotSpot WiFi management infoleak. [1day] – Antamedia Internet Cafe Denial of Service. [1day] – GrapeCity spreadcom ActiveX Control Remote Code Execution Vulnerability. [1day] – MiniWeb HTTP server Directory Traversal. [1day]
2018-Jul-30 2.79 Agora new 5 modules:
2018-Jun-25 2.78 Agora:
– Seagate Media Server in Seagate Personal Cloud has Path traversal vulnerability. public
– TerraMaster TOS 3.0.33 – Unauthenticated Remote Command Execution. public
– Typesetter CMS Arbitrary File Disclosure. [1day] – Typesetter CMS Directory Listing. [1day]
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 – Remote Code Execution [CVE-2018-7600] CloudMe Sync <= v1.10.9 Remote Buffer Overflow [CVE-2018-6892] AxxonSoft Axxon Next – DirTrav [CVE-2018-7467] Wordpress Fastest Cache <= 0.8.7.4 Blind SQL Injection
– ManageEngine Applications Manager – Remote Command Execution
– Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 – Directory Traversal
– Softros Network Time System Server 2.3.4 – Denial of Service
– Trustwave Secure Web Gateway v.188.8.131.52 – Unauthorized Access [CVE-2017-18001] – Microsoft Word .RTF RCE [CVE-2017-0199] – phpCollab 2.5.1 – Unauthenticated File Upload / Remote Code Execution [CVE-2017-6090] – VideoIQ Camera – Local File Disclosure
– WordPress Core DoS CVE-2018-6389 + Smart Google Code plugin SQLi
– phpMyFAQ 2.9.9 RCE
– Netgear ReadyNAS Surveillance Unauth RCE
– Cisco Prime Collaboration Provisioning Auth Bypass / Remote Code Execution
– Apache Tomcat CVE-2017-12617
– Zoho ManageEngine Applications Manager 13 SQL Injection [CVE-2017-16543] – Unitrends UEB 9.1 – Unauthenticated Remote Code Execution [CVE-2017-12477] – Belkin NetCam F7D7601 – Remote Command Execution