header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Computer Associates (CA) Brightstor Backup Remote Procedure Call Server DoS (catirpc.dll)

CATIRPC.dll does not properly handle TADDR2UADDR procedures used in RPC communications with the CA RPC Server (Catirpc.exe). This leads to a condition where a null memory pointer is dereferenced. This appears to be only a DoS, but please prove me otherwise. This was tested on BrightStor ARCserve Backup 11.5.2.0 (SP2).

ACGVannu <= 1.3 (index2.php) Remote User Pass Change Vulnerability

The ACGVannu version 1.3 and below in the index2.php file is vulnerable to a remote user password change vulnerability. By sending a specially crafted request to the index2.php file with the 'id' parameter set to a specific user ID, an attacker can change the password of the targeted user.

Authentication bypass (SSRF) and local file disclosure

The Plex Media Server '/system/proxy' functionality fails to properly validate pre-authentication user requests, allowing unauthenticated attackers to make the Plex Media Server execute arbitrary HTTP requests. By requesting content from 127.0.0.1 an attacker can bypass all authentication and execute commands with administrative privileges. Additionally, due to insufficient input validation, arbitrary local files can be disclosed, including files that contain passwords and other sensitive information.

Recent Exploits: