Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-8609 PoC — Android Settings应用程序权限许可和访问控制漏洞

Source
Associated Vulnerability
Title:Android Settings应用程序权限许可和访问控制漏洞 (CVE-2014-8609)
Description:The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.
Description
pendingintent vulnerability
Readme
# CVE-2014-8609-POC
-pendingintent vulnerability


شرح لكيفية عمل الثغره مع طريقة الاستغلال, وهي من الثغرات الاكثر شيوعا في تطبيقات الاندرويد، ويمكنك من خلالها الوصول لثغرات اكثر بطريقه احترافيه

POC

https://user-images.githubusercontent.com/54814433/126043657-053de0fb-5723-410d-b03a-6f0be860f84b.mp4

File Snapshot

[4.0K] /data/pocs/d036d763e51ecb549c431c27358f549b52679806 ├── [2.8M] 0xMaz CVE-2014-8609.pdf ├── [2.1M] POC.mp4 └── [ 424] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →