header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Exploit Buffer Overflow Altarsoft Audio Converter 1.1(SEH)

This exploit is for a buffer overflow vulnerability in Altarsoft Audio Converter version 1.1. It allows an attacker to execute arbitrary code by sending a specially crafted file. The vulnerability is triggered when the program tries to handle a long file name.

Local File Include (LFI) vulnerability in Google Urchin

Google Urchin is vulnerable to a Local File Include (LFI) vulnerability that allows arbitrary reading of files. The vulnerability is caused by improper filtering of included files, which are stored under $INSTALL_PATH. By modifying the 'gfid' parameter in a GET request, an attacker can read any file on the host.

Apache Archiva Cross-site Request Forgery Vulnerability

Apache Archiva affects from Cross-site Request Forgery. Application don't check which form sends credentials. Technically, attacker can create a specially crafted page and force archiva administrators to view it and change their credentials. For prevention from CSRF vulnerabilities, application needs anti-csrf token, captcha and asking old password for action like change password. Vulnerability patched by the Apache Archiva Team.

CSRF vulnerabilities in Linksys routers

There are multiple unpatched CSRF vulnerabilities in the administration interfaces for various Linksys routers. Exploits are available that allow remote administration of the router and changing the password to '__pwn3d__'. The victim does not necessarily need to be authenticated since the default passwords for all routers are known to be 'admin'. Most browsers provide some degree of protection against these attacks.

Recent Exploits: