header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

HP Data Protector EXEC_BAR Remote Command Execution

The omniinet service in HP Data Protector is vulnerable to remote command execution. By sending a malicious EXEC_BAR packet, an attacker can force the service to run arbitrary commands on the target system. This can lead to complete compromise of the remote host. The vulnerability can be exploited by sending two specific arguments to the omniinet service. The exploit creates a new Windows account and adds it to the local Administrators group.

Cross-Site Scripting Vulnerabilities in ManageEngine EventLog Analyzer

Multiple cross-site scripting vulnerabilities exist in ManageEngine EventLog Analyzer, allowing an attacker to execute arbitrary script code in the browser of a user visiting the affected site. This can lead to the theft of authentication credentials and enable further attacks.

InstantHMI – EoP: User to ADMIN

During a standard installation of InstantHMI, the installer automatically creates a folder named "IHMI-6" in the root drive with incorrect default permissions. AUTHENTICATED USERS are given WRITE permission, allowing them to replace binaries or plant malicious DLLs to obtain elevated, administrative level privileges.

SAP Internet Transaction Server Cross-Site Scripting Vulnerability

SAP Internet Transaction Server (ITS) is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting this issue would allow an attacker to steal cookie-based credentials and to launch other attacks.

Hosting Controller Cross-Site Scripting Vulnerability

Hosting Controller is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application. An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Recent Exploits: