header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Moodle 1.9.3 Remote Code Execution

A Remote Code Execution exists in Moodle 1.9.3. A Remote Code Execution (RCE) vulnerability has been found in filter/tex/texed.php. In order to exploit this vulnerability register_globals must be enabled as the 'TeX Notation' filter. The parameter '$pathname' is not sanitized and can be used to inject arbitrary commands.

Social Groupie Exploit

After registering in the site, the attacker can go to the photos section (http://www.site.me/Photos/photos.php) and create a new album (http://www.site.me/Photos/create_album.php). The attacker can then upload a malicious shell file (shell.jpg.php or shell.php) which will be located at http://www.site.me/Member_images/

Microsoft Visual Basic ActiveX Controls mscomct2.ocx Animation Object Buffer Overflow (CVE-2008-4255) PoC

Microsoft Visual Basic ActiveX Controls mscomct2.ocx Animation Object is vulnerable to a buffer overflow vulnerability. An attacker can exploit this vulnerability by creating a malicious .AVI file and serving it via an UNC path. This will allow the attacker to execute arbitrary code on the vulnerable system.

ASP-CMS v.1.0 Sql Injection Vulnerability

A vulnerability in ASP-CMS v.1.0 allows an attacker to inject malicious SQL commands into the application. This can be exploited to gain access to the application's database and potentially gain access to sensitive information. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'cha' parameter of the 'index.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands. This can be used to gain access to the application's database and potentially gain access to sensitive information.

Recent Exploits: