header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

FortiRecorder 6.4.3 – Denial of Service

This exploit allows an attacker to cause a denial of service (DoS) on FortiRecorder version 6.4.3 and below as well as versions 6.0.11 to 6.0.0. By sending a specially crafted payload to the target, the attacker can trigger a failure and disrupt the normal functioning of the system.

SOUND4 LinkAndShare Transmitter 1.1.2 – Format String Stack Buffer Overflow

The application suffers from a format string memory leak and stack buffer overflow vulnerability because it fails to properly sanitize user supplied input when calling the getenv() function from MSVCR120.DLL resulting in a crash overflowing the memory stack and leaking sensitive information. The attacker can abuse the username environment variable to trigger and potentially execute code on the affected system.

Control Web Panel 7 (CWP7) v0.9.8.1147 – Remote Code Execution (RCE)

This exploit allows an attacker to execute arbitrary code on a vulnerable Control Web Panel (CWP) version 0.9.8.1147 and below. By sending a specially crafted request to the /login/index.php endpoint, the attacker can inject a malicious cURL command that will be executed by the server. This can lead to unauthorized access, data leakage, and further compromise of the system.

bgERP v22.31 (Orlovets) – Cookie Session vulnerability & Cross-Site Scripting (XSS)

The bgERP system suffers from unsecured login cookies in which cookies are stored as very sensitive login and also login session information! The attacker can trick the already login user and can steal the already generated cookie from the system and can do VERY DANGEROUS things with the already stored sensitive information. This can be very expensive for all companies which are using this system, please be careful! Also, this system has a vulnerable search parameter for XSS-Reflected attacks!

Recent Exploits: