The vulnerability in Wordpress Plugin Background Image Cropper v1.2 allows remote attackers to execute arbitrary code on the target system. By uploading a malicious PHP file, an attacker can run commands on the server remotely. This vulnerability has a CVE ID pending assignment.
The vulnerability exists in the ofrs/admin/index.php script due to inadequate user input handling during the login process.
Electrolink FM/DAB/TV Transmitter devices with web version 01.09, 01.08, 01.07, display version 1.4, 1.2, control unit version 01.06, 01.04, 01.03, and firmware version 2.1 are vulnerable to a pre-authentication MPFS image remote code execution. An attacker could exploit this vulnerability to execute arbitrary code on the affected system.
TinyBB Version 1.2 is vulnerable to SQLi. The exploit can be performed by appending ' or 'a'='a to the profile ID parameter in the URL.
The Easy Address Book WebServer 1.2 is vulnerable to CSRF attacks. An attacker can trick a user into visiting a malicious website that performs actions on the Easy Address Book WebServer on behalf of the user without their consent or knowledge.
This exploit allows remote attackers to bypass ASLR and DEP protections in ProSSHD 1.2, leading to unauthorized access.
This exploit allows an attacker to remotely crash the iFTPStorage application on iPhone and iPod. By sending a large buffer of 'A' characters, the application crashes and becomes unresponsive.
The SN News <= 1.2 application is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain unauthorized access to the application's database.
This exploit allows an attacker to perform a Denial of Service attack on the Dlink DSL-2650U router. By sending a specially crafted request to the 'diagpppoe.cgi' script with a long string of characters, the router crashes and becomes unresponsive.
This exploit is used to perform a Denial of Service attack on SpoonFTP version 1.2. It sends a specially crafted packet to the FTP server, causing it to crash and become unresponsive.