header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

DiY-CMS 1.0 Remote File Inclusion

The DiY-CMS 1.0 version is vulnerable to remote file inclusion. By exploiting this vulnerability, an attacker can execute arbitrary code by including remote files in the vulnerable PHP scripts. The vulnerability exists in the control.block.php, index.php, and general.functions.php files. The attacker can provide a malicious shell in the 'lang' and 'main_module' parameters, allowing them to execute arbitrary code on the target system.

Firefox location.QueryInterface() Code Execution (Mac OS X)

This module exploits a code execution vulnerability in the Mozilla Firefox browser. To reliably exploit this vulnerability, we need to fill almost a gigabyte of memory with our nop sled and payload. This module has been tested on OS X 10.3 with the stock Firefox 1.5.0 package.

Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)

This exploit allows an attacker to hijack the DLL in Microsoft Office PowerPoint 2007, specifically the rpawinet.dll. By executing a malicious PowerPoint file (.odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx files), the attacker can execute arbitrary code, in this case, launching the calculator.

Roxio MyDVD 9 DLL Hijacking Exploit (HomeUtils9.dll)

This exploit targets Roxio MyDVD 9 software and utilizes a DLL hijacking technique. By placing a malicious DLL file named HomeUtils9.dll in the same directory as the vulnerable software, an attacker can execute arbitrary code with the privileges of the user running the software. This can lead to unauthorized access, privilege escalation, or remote code execution.

Roxio Creator DE DLL Hijacking Exploit (HomeUtils9.dll)

This exploit allows an attacker to hijack the HomeUtils9.dll file in Roxio Creator DE. By exploiting this vulnerability, an attacker can execute arbitrary code with the privileges of the user running the affected software.

Skype <= 4.2.0.169 DLL Hijacking Exploit (wab32.dll)

This exploit allows an attacker to hijack the DLL file used by Skype version 4.2.0.169 and earlier, specifically the wab32.dll file. By placing a malicious wab32.dll file in the appropriate directory, an attacker can execute arbitrary code when Skype is launched.

Recent Exploits: