Skip to content

Instantly share code, notes, and snippets.

@VAMorales
VAMorales / BridgeHeadFileStoreApacheAxis2RCE.md
Created April 24, 2026 11:57
BridgeHead Software - BridgeHead FileStore Apache Axis2 Default Credentials RCE (CVE-2026-39920)

Exploit Title: BridgeHead Software - BridgeHead FileStore Apache Axis2 Default Credentials RCE

Disclosure Date: 4/24/2026

Exploit Authors: Victor A. Morales of GM Sectec, Corp.

Known Affected Versions: < 24A

Description

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

@VAMorales
VAMorales / Kofax Capture - Unauthenticated NET Remoting vulnerabilities.md
Created April 23, 2026 14:32
Kofax Capture - Unauthenticated File Read/Write and SMB coercion via .NET Remoting

Exploit Title: Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting

Disclosure Date: 4/23/2026

Exploit Authors: Victor A. Morales of GM Sectec, Corp.

Known Affected Versions: 6.0.0.0

Description

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service (C:\Kofax\CaptureSS\ServLib\Bin\ACSvc.exe) that is accessible without authentication and uses a default, publicly known endpoint identifier. By modifying the PoC of Code-White's RemotingClient_MBRO_Lazy.exe program to implement a custom channel sink to redirect .NET Remoting traffic to the correct host, an unauthenticated remote attacker can exploit .NET Remoting object unma

@VAMorales
VAMorales / Unisys-WebPerfect Image Suite-CVE-2026-39906-CVE-2026-39907.md
Created April 23, 2026 14:14
Unisys - WebPerfect Image Suite - CVE-2026-39906 / CVE-2026-39907

Exploit Title: Unisys - WebPerfect Image Suite NTLMv2 Hash Leakage via .NET Remoting

Disclosure Date: 4/23/2026

Exploit Authors: Victor A. Morales of GM Sectec, Corp.

Known Affected Versions: 3.0.3960.22810, 3.0.3960.22604

Description

Deprecated .NET Remoting technology on an ephemeral network reachable port is used by the program Unisys.SOA.PerfectImageService.exe. Modifying the PoC of Code-White's RemotingClient_MBVO.exe program to implement a custom channel sink to redirect .NET Remoting traffic to the correct host, it was determined that the System.Media.SoundPlayer class technique allows SMB coercion by supplying a remote UNC path to leak the NTLMv2 hash of the account running the service.

@VAMorales
VAMorales / Entrust Security Bulletin E25-002.md
Created April 24, 2025 21:27
Entrust Security Bulletin E25-002

Entrust Security Bulletin E25-002

Unauthenticated Arbitrary File Reading and Arbitrary Code Execution Vulnerability in Printer Manager Systems


Who Should Read This Bulletin

Customers with printers running D3.18.4-3 or prior firmware with Printer Manager enabled (the default configuration). Customers with this configuration are advised to upgrade to the latest version and apply the remediation steps described herein.

Exploit Title: Hyland Software OnBase - Unauthenticated Remote Code Execution via .NET Deserialization

Disclosure Date: 04/09/2025

CVEID: CVE-2025-34153

Exploit Authors: Victor A. Morales, GM Sectec Inc.

Vendor Homepage: https://www.hyland.com/

Affected Versions: < 17.0.2.87 (other versions may be affected)

Known Fixed Version: 24.1 (earlier versions may contain a fix)

Description

# Exploit Title: AspectSoftware Unified IP Unified Director - Unauthenticated File Upload and SMB Coercion Attack
# Date: 12/08/2024
# CVE-2024-56973
# Exploit Authors: Victor A. Morales, GM Sectec Inc.
# Vendor Homepage: https://www.alvaria.com/
# Affected Versions: < 7.4 SP2
# Platform: Windows
# Description (Unauthenticated File Upload)
The file ProcessUploadFromURL.jsp used in Unified IP Unified Director below versions 7.4 SP2, allows arbitrary files to be uploaded from a remote server to the same directory where ProcessUploadFromURL.jsp is located without prior authentication. This allows an attacker to upload a malicious JSP file by specifying a remote server and file in the source and filename parameters respectively. The file can then be accessed by navigating to "/UnifiedDirector/<file>", leading to remote code execution.
@VAMorales
VAMorales / CVE-2024-39341_CVE-2024-39342.txt
Created September 20, 2024 23:16
Instant Financial Issuance (On Premise) Software (formerly CardWizard) - Sensitive Information Disclosure (CVE-2024-39341) / Hardcoded Cryptographic Keys (CVE-2024-39342)
# Exploit Title: Instant Financial Issuance (On Premise) Software (formerly CardWizard) - Sensitive Information Disclosure
# Date: 08/20/2024
# Exploit Authors: Victor A. Morales, Omar A. Crespo, GM Sectec Inc.
# Vendor Homepage: https://trustedcare.entrust.com/login
# Version: 6.10.0, 6.9.0, 6.9.1, 6.9.2, 6.8.x and older
# Instant Financial Issuance as a Service (8.x) is not affected.
# Fix: Entrust Security Bulletin E24-003
# Tested on: Windows Server 2019 Standard Build 17763
# CVE: CVE-2024-39341