header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

FleaHttpd Remote Denial Of Service Exploit

FleaHttpd is a http daemon written from scratch in C. When working as a static file server, data show that under certain condition, fleahttpd's speed for static file retrieving can be three times faster than Apache2. This exploit uses a socket connection to send a packet to the server, which causes the server to crash.

Authenex A-Key/ASAS Web Management Control 3.1.0.2 (latest) – Time-based SQL Injection

An attacker can exploit this vulnerability by sending a specially crafted SQL query to the application. The query will cause the application to wait for a certain amount of time before responding. This can be used to determine if the application is vulnerable to SQL injection.

Firefox <= 8.0 null pointer dereference PoC exploit

A null pointer dereference vulnerability exists in Firefox versions <= 8.0 due to improper validation of user-supplied input. An attacker can exploit this vulnerability by crafting a malicious HTML page and convincing the victim to open it. This will cause the application to crash and potentially allow arbitrary code execution.

Pixie CMS 1.01 – 1.04 “Referer” Blind SQL Injection

A Blind SQL Injection vulnerability exists in Pixie CMS versions 1.01 - 1.04. An attacker can send a specially crafted HTTP request with a malicious Referer header to the vulnerable application in order to execute arbitrary SQL commands. If the condition is true, the application will respond with a timeout of ~5 seconds.

WordPress AdRotate plugin <= 3.6.6 SQL Injection Vulnerability

The WordPress AdRotate plugin version 3.6.6 is vulnerable to a SQL injection vulnerability due to incorrect usage of the wpdb->prepare() function. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with a Base64 encoded payload in the 'track' parameter. This will allow the attacker to execute arbitrary SQL queries on the underlying database.

Optima APIFTP Server <= 1.5.2.13 Vulnerabilities

Optima is a suite of automation software for controlling PLC via SCADA/HMI interface. APIFTP Server is a file server for working with remote files located on shared folders. NULL pointer exploitable through too long path names. The effect is the displaying of a MessageBox with the error and the continuing of the execution that will lead to a stack exaustion after some seconds and the termination of the server. Endless loop with CPU at 100% caused by incomplete packets.

Recent Exploits: