header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Multiple vulnerabilities in 360 Web Manager 3.0

360 Web Manager 3.0 makes use of a panel manager which uses a simple file manager, this script don't require any authorization at all to upload, list, or even delete files. By looking the source code we can find the internal path of the application right next to: 'inpAssetBaseFolder0'. Through a forged post we can manipulate the path of the folder to list or delete. Also when uploading a file we can easily change the path of the folder by changing the 'inpCurrFolder2' parameter (there's no restriction to upload php files!).

First Escort Marketing CMS Multiple SQL Injection Vulnerabilities

Multiple SQL Injection vulnerabilities exist in First Escort Marketing CMS, which could allow an attacker to execute arbitrary SQL commands on the underlying database. The vulnerabilities exist in the banner.php, escort-profile.php, write_review.php, booking-form.php, and gallery_escorts.php scripts, when user-supplied input is not properly sanitized before being used in a SQL query. An attacker can exploit these vulnerabilities by sending a maliciously crafted HTTP request to the vulnerable scripts.

docuFORM Mercury WebApp 6.16a Multiple Cross-Site Scripting Vulnerabilities

The Mercury Web Application suffers from multiple XSS vulnerabilities when parsing user input thru the GET parameter 'this_url' and the POST parameter 'aa_sfunc' in f_state.php, f_list.php, f_job.php and f_header.php scripts. Attackers can exploit these weaknesses to execute arbitrary HTML and script code in a user's browser session.

Ultimate eShop Error Based SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a malicious payload to the vulnerable parameter 'go' in the URL. The payload 'ERROR BASED INJECTION' will cause an error in the application which will reveal the underlying database structure and allow the attacker to extract sensitive information.

Adobe Flash player Action script type confusion exploit (DEP+ASLR bypass)

For exploitation purpose on recent protections on windows 7 without any 3rd party (well flash is not 3rd party todays) , it is possible to use the same bug many times to leak the imageBase address and payload address. In our exploit we used three confusion to read String Objects address and accordingly imagebase address. Step1: read shellcode string object pointer by confusing it with uint and use it to leak ImageBase. Step2: leak address of the shellcode with the same pointer and NewNumber trick. Step3: send imageBase & shellcode address as parameters to the RopPayload function, develop Rop payload string and again confuse the return value with uint to read address of RopPayload string. Step4: send address of the rop payload as parameters to the last confused function that confuses string type with class object. And thus address of our rop payload will be used as vtable in the fake class object. Note: In using strings as a buffer for shellcode in action script, it is important to use alphanumeric characters because the toString method converts our ascii character set to uincode thus make our shellcode unusable.

Exploit for Wireshark 1.4.1-1.4.4

This exploit is for Wireshark 1.4.1-1.4.4. It is a buffer overflow exploit which uses a payload of calc.exe and a non-ASLR enabled wireshark module. It has been tested on Windows XP SP2 and SP3 but should work on every Windows with DEP off. It has been fixed in the latest version 1.4.5.

osPHPSite SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable application. For example, an attacker can send a malicious SQL query to the vulnerable application as a part of the 'id' parameter value in the following URL: http://www.[sitename].com/index.php?id=[Sql Injection]. This can allow the attacker to access or modify the application's data, or even execute system commands.

Recent Exploits: