header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Information Disclosure in GeoVision GV-ASManager

An information disclosure vulnerability has been found in the GeoVision GV-ASManager web application with version 6.1.0.0 or lower. This vulnerability allows unauthorized access to sensitive information within the application, such as user accounts and clear text passwords, potentially leading to unauthorized access to monitoring cameras, access cards, and other critical data.

Broken Access Control in GeoVision GV-ASManager

The vulnerability exists in GeoVision GV-ASManager web application version 6.1.0.0 or below. An attacker with network access and a low privilege account can perform unauthorized actions like enabling/disabling accounts, creating new accounts, modifying privileges, and accessing resources. After privilege escalation, the attacker can access monitoring cameras, employee information, change configurations, disrupt services, clone access control data, and retrieve cleartext passwords for further attacks.

Broker FTP Server Denial of Service Vulnerabilities

It has been reported that Broker FTP Server may be prone to multiple denial of service vulnerabilities. These issues may allow a remote attacker to cause the software to crash or hang. Broker FTP Server version 6.1.0.0 has been reported to be prone to these issues, however, other versions may be affected as well.

IpSwitch WS_FTPSERVER with SSH remote Buffer Overflow

A buffer overflow vulnerability exists in IpSwitch WS_FTPSERVER with SSH when a maliciously crafted CD command is sent to the server. This can be exploited to cause a stack-based buffer overflow by sending an overly long string to the server. Successful exploitation could allow remote attackers to execute arbitrary code on the vulnerable system.

WS_FTP Server Manager Authentication-Bypass and Information-Disclosure Vulnerabilities

WS_FTP Server Manager is prone to an authentication-bypass vulnerability and an information-disclosure vulnerability. An attacker can exploit these issues to gain unauthorized access to the affected application and gain access to potentially sensitive information.

IBM Tivoli Storage Manager (TSM) Local Root

When IBM TSM communicates with the suid root backup client dsmtca, it is handled through pipes. The function GeneratePassword() does not perform boundary checking, which can lead to a classic stack based buffer overflow - making local code execution possible. An attacker can achieve arbitrary code execution by placing his shellcode in the LANG environment variable, and then overwrite the return address of GeneratePassword() with the known address that the value is copied to.

Recent Exploits: