header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Vulnerability in bash allowing inadvertently running commands in the path to the current working directory

A vulnerability in bash allows inadvertently running commands embedded in the path to the currently working directory. If an unsuspecting user enters a directory created by some malicious user with embedded commands, and their prompt (PS1) contains 'w' or 'W', and the prompt is displayed, the commands will be executed. The vulnerability is in the parsing of the 'w' and 'W' escape codes. As the prompt must be displayed unattended shell scripts are not vulnerable.

FreeNAC version 3.02 SQL Injection and XSS Vulnerabilities

Multiple parameters in FreeNAC version 3.02 are vulnerable to reflective cross-site scripting. The affected parameters are comment, mac, graphtype, type, and name. An attacker can inject malicious scripts into these parameters, which can be executed in the user's browser. This can lead to various attacks such as stealing sensitive information, session hijacking, or defacing the website.

BulletProof FTP Client 2010 – Buffer Overflow Vulnerability

A Buffer Overflow vulnerability is detected on BulletProof FTP Client v2010.75.0.76. The vulnerability is located in the main executeable bpftpclient.exe. During the start of the application the value LogFileName from the registry key [HKEY_CURRENT_USER/Software/BulletProof Software/BulletProof FTP Client 2010/Options] is read. When inserting an oversized value to the registry value a buffer overflow is triggered. The victim only needs to start the application.

FlashFXP v4.1.8.1701 – Buffer Overflow Vulnerability

A Buffer Overflow Vulnerability is detected on FlashFXPs Software Client v4.1.8.1701. The vulnerability is located when processing to force a ListIndex Out of Bound(s) exception which allows to overwrite ecx & eip of the affected software process. Successful exploitation can result in process compromise.

Recent Exploits: