header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

IBM Security Verify Access 10.0.0 – Open Redirect Vulnerability in OAuth Flow

By tricking a user into visiting a malicious website, an attacker could exploit this vulnerability in IBM Security Verify Access 10.0.0 - 10.0.8 to redirect the user to a different site that appears legitimate, potentially leading to the disclosure of sensitive information or enabling further attacks.

Multiple Security Vulnerabilities in Halon Security Router

The Halon Security Router is affected by multiple vulnerabilities including Reflected XSS, CSRF, and Open Redirect. The Reflected XSS vulnerability allows an attacker to inject malicious scripts into the application, potentially leading to unauthorized access or data theft. The CSRF vulnerability allows an attacker to trick a user into performing unwanted actions on behalf of the user, potentially leading to unauthorized changes in the system. The Open Redirect vulnerability allows an attacker to redirect users to malicious websites, potentially leading to phishing attacks or malware downloads.

Cart Engine 3.0 Multiple Vulnerabilities

Using a specially crafted HTTP request, it is possible to exploit a lack in the validation of the “item_id[0]” and “item_id[]” input parameters of cart.php page. Successful exploitation of the vulnerabilities results in read sensitive data from the database and, in some cases, execute administration operation on the database or issue commands to the operating system. Using a specially crafted HTTP request, it is possible to exploit a lack in the neutralization of multiple pages output which includes the user submitted content. Successful exploitation of the vulnerabilities, results in the execution of arbitrary HTML and script code in the user’s browser in the context of the victim user's session trough a “Reflected XSS”. Using a specially crafted HTTP request, it is possible to redirect the normal browsing of users to a malicious site by modifying untrusted URL input in Referer HTTP header parameter in index.php, cart.php, msg.php and page.php pages. Successful exploitation of the vulnerabilities results in phishing scam, user credential theft, malware dissemination.

Symantec SEPM Multiple Vulnerabilities

The management console for SEPM contains a number of security vulnerabilities that could be used by a lower-privileged user or by an unauthorized user to elevate privilege or gain access to unauthorized information on the management server. Exploitation attempts of these vulnerabilities requires access to the SEP Management console. XSS can bypass the 'http-only' cookie protection because the SEPM application writes and stores the session ID within various javascript functions used by the application within the DOM thereby exposing them directly to the XSS attack.

Recent Exploits: