header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

FactoryLink vrn.exe Opcode 9 Buffer Overflow

This module exploits a stack buffer overflow in FactoryLink 7.5, 7.5 SP2, and 8.0.1.703. By sending a specially crafted packet, an attacker may be able to execute arbitrary code due to the improper use of a vsprintf() function while processing the user-supplied text field. Originally found and posted by Luigi Auriemma.

Cachelogic Expired Domains Script 1.0 multiple security vulnerabilities

Cachelogic Expired Domains Script version 1.0 is vulnerable to Full Path Disclosure, Reflected Cross-Site Scripting (XSS) and SQL Injection. An attacker can exploit these vulnerabilities to gain access to sensitive information, execute arbitrary code, and inject malicious SQL queries.

Black Ice Cover Page ActiveX Control Arbitrary File Download

This module allows remote attackers to place arbitrary files on a users file system by abusing the "DownloadImageFileURL" method in the Black Ice BIImgFrm.ocx ActiveX Control (BIImgFrm.ocx 12.0.0.0). Code exeuction can be acheived by first uploading the payload to the remote machine, and then upload another mof file, which enables Windows Management Instrumentation service to execute the binary.

0-Day WPtouch WordPress Plugin 1.9.27 URL redirection

A 0-day vulnerability exists in the WPtouch WordPress Plugin 1.9.27, which allows attackers to redirect users to malicious websites. An attacker can craft a malicious URL with the ‘wptouch_view’ and ‘wptouch_redirect’ parameters, which can be used to redirect users to a malicious website. The malicious URL can be used in phishing campaigns to steal user credentials.

DreamBox DM800 Arbitrary File Download Vulnerability

Dreambox suffers from a file download vulnerability thru directory traversal with appending the '/' character in the HTTP GET method of the affected host address. The attacker can get to sensitive information like paid channel keys, usernames, passwords, config and plug-ins info, etc. By default, web application is running by root, so catch shadow is very easy.

Abysssec Public Exploit

This module exploits a code execution vulnerability in Mozilla Firefox <= 3.6.16 caused by nsTreeSelection element. The specific flaw exists within the way Firefox handles user defined functions of a nsTreeSelection element. When executing the function invalidateSelection it is possible to free the nsTreeSelection object that the function operates on. Any further operations on the freed object can result in remote code execution. This exploit module is only tested on win7 and used a Another JAVA ROP to defeat DEP/ASLR (due to there is no more non-aslr module in Firefox) and in my tests works reliably on Windows7. There is two version of this exploit XP and 7 and both use different method that used in MSF Exploit bounty !

Black Ice Fax Voice SDK v12.6 – integer dereference code execution exploit

The vulnerability is an integer overflow in the fax.ocx section of Black Ice Fax Voice SDK v12.6. This leads to a dereference vulnerability which can be exploited by calling the vulnerable methods GetFirstItem() and GetItemQueue().

Blackice Cover Page SDK insecure method DownloadImageFileURL() exploit

This module allows remote attackers to place arbitrary files on a users file system by abusing the "DownloadImageFileURL" method in the Black Ice BIImgFrm.ocx ActiveX Control (BIImgFrm.ocx 12.0.0.0). This issue is also reported in BIDIB.ocx (10.9.3.0) within the Barcode SDK.

Recent Exploits: