The exploit allows an attacker to perform Remote Code Execution on qBittorrent version 5.0.1 and below by intercepting the host machine using a Man-In-The-Middle (MITM) attack. By running the Proof of Concept (PoC) exploit, the attacker can inject any malicious executable instead of the legitimate Python installer.
The Klinza Professional CMS version 5.0.1 is vulnerable to a remote file inclusion vulnerability in the show_hlp.php file. An attacker can exploit this vulnerability to include a remote file and execute arbitrary code on the target system.
PluXml is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
The exploit is a stack overflow vulnerability in Media Player Classic 6.4.9. It allows an attacker to execute arbitrary code by providing a specially crafted MP4 file. The vulnerability was discovered and exploited by SYS 49152. It has been tested on Windows XP SP2 ENG and provides a shell on port 49152.
This exploit allows an attacker to perform SQL injection in WordPress Plugin AN_Gradebook version 5.0.1 or earlier. By exploiting this vulnerability, an attacker can gain unauthorized access to the database.
The vulnerability allows a normal admin to escalate their privileges to super admin by exploiting a SQL injection vulnerability in Affiliate Me version 5.0.1. The vulnerability can be exploited by sending a specially crafted request to the admin.php file with an injected query.
The 'indexu' application is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Using the window.external.NavigateAndFind() function it is possible for a remote server to execute arbitrary javascript code on an Internet Explorer client machine in the local security context. This function is used to load a web document and search it for specific strings, displaying the results in a secondary frame. However, the function will accept URLs of the form 'javascript:', and should such a URL to passed to the function, the javascript is executed in the security context of the content of the secondary frame, and has access to that frame's current content. This weakness could be used to retrieve pwl files, the local SAM database, cookies or any other locally stored information that the user has read access to. The attack could be made via the web, or in an HTML email or newsgroup posting.
The 'klinza professional cms' project is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Post-it is vulnerable to a DoS condition when a long list of characters is being used when creating a note. Successful exploitation will cause the application to stop working. The exploit has been tested against iOS 14.2.