This module exploits a stack buffer overflow in FactoryLink 7.5, 7.5 SP2, and 8.0.1.703. By sending a specially crafted packet, an attacker may be able to execute arbitrary code due to the improper use of a vsprintf() function while processing the user-supplied text field. Originally found and posted by Luigi Auriemma.
Cachelogic Expired Domains Script version 1.0 is vulnerable to Full Path Disclosure, Reflected Cross-Site Scripting (XSS) and SQL Injection. An attacker can exploit these vulnerabilities to gain access to sensitive information, execute arbitrary code, and inject malicious SQL queries.
Guest level privilages, or higher, are required. http://localhost/[PATH]/users.php?action=groups&order=-1&userids=-1) union select 1,concat(user_name,0x3a,user_passhash),user_email,user_firstname,user_lastname,6,7 from users,groups where (1=1
This module allows remote attackers to place arbitrary files on a users file system by abusing the "DownloadImageFileURL" method in the Black Ice BIImgFrm.ocx ActiveX Control (BIImgFrm.ocx 12.0.0.0). Code exeuction can be acheived by first uploading the payload to the remote machine, and then upload another mof file, which enables Windows Management Instrumentation service to execute the binary.
A 0-day vulnerability exists in the WPtouch WordPress Plugin 1.9.27, which allows attackers to redirect users to malicious websites. An attacker can craft a malicious URL with the ‘wptouch_view’ and ‘wptouch_redirect’ parameters, which can be used to redirect users to a malicious website. The malicious URL can be used in phishing campaigns to steal user credentials.
Dreambox suffers from a file download vulnerability thru directory traversal with appending the '/' character in the HTTP GET method of the affected host address. The attacker can get to sensitive information like paid channel keys, usernames, passwords, config and plug-ins info, etc. By default, web application is running by root, so catch shadow is very easy.
This module exploits a code execution vulnerability in Mozilla Firefox <= 3.6.16 caused by nsTreeSelection element. The specific flaw exists within the way Firefox handles user defined functions of a nsTreeSelection element. When executing the function invalidateSelection it is possible to free the nsTreeSelection object that the function operates on. Any further operations on the freed object can result in remote code execution. This exploit module is only tested on win7 and used a Another JAVA ROP to defeat DEP/ASLR (due to there is no more non-aslr module in Firefox) and in my tests works reliably on Windows7. There is two version of this exploit XP and 7 and both use different method that used in MSF Exploit bounty !
Local File Inclusion vulnerability within IF-CMS 2.07 which allows remote attackers to include and execute arbitrary local files via a ../ at the newlang parameter within the index.php page.
The vulnerability is an integer overflow in the fax.ocx section of Black Ice Fax Voice SDK v12.6. This leads to a dereference vulnerability which can be exploited by calling the vulnerable methods GetFirstItem() and GetItemQueue().
This module allows remote attackers to place arbitrary files on a users file system by abusing the "DownloadImageFileURL" method in the Black Ice BIImgFrm.ocx ActiveX Control (BIImgFrm.ocx 12.0.0.0). This issue is also reported in BIDIB.ocx (10.9.3.0) within the Barcode SDK.