This exploit allows an attacker to execute arbitrary commands on a vulnerable Versant server version <= 7.0.1.3. The exploit is a zip file containing a proof-of-concept exploit code which can be used to execute arbitrary commands on the vulnerable server. The exploit code is written in C and can be compiled on any platform.
MiniWebSvr 0.0.9a is vulnerable to a directory transversal attack. By sending a specially crafted HTTP request, an attacker can read arbitrary files from the server.
A vulnerability in the album.php script of the Dynamic Photo Gallery (foto-gallery.php) allows an attacker to inject arbitrary SQL commands via the albumID parameter.
Livebox router is vulnerable to a remote (but from local network, because firewall working..) buffer overflow DoS attack to FTP service. The exploit sends an evil buffer of 1000 bytes to the FTP service, causing a denial of service.
A vulnerability exists in phpComasy 0.8, which allows a remote attacker to inject arbitrary SQL commands via the mod_project_id parameter in a index.php?id=7&mod_action=project_detail&mod_project_id= request. An attacker can exploit this vulnerability to gain access to the database and compromise the application.
An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameter 'userid' in the 'index.php' page. This can allow the attacker to gain access to the database and extract sensitive information such as usernames and passwords.
An attacker can exploit a SQL injection vulnerability in Mambo com_Musica component. The vulnerability is due to insufficient sanitization of user-supplied input to the 'id' parameter of the 'index.php' script when 'tasko' and 'task' parameters are set to 'viewo' and 'view2' respectively. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation may allow an attacker to gain access to the affected application, disclose sensitive information, modify data, or exploit further vulnerabilities in the underlying database or operating system.
A vulnerability in Koobi CMS 4.3.0 - 4.2.3 allows an attacker to inject arbitrary SQL commands via the 'categ' parameter in the 'index.php' script.
This exploit is a buffer overflow vulnerability in the Symantec BackupExec Calendar Control (PVCalendar.ocx) ActiveX control. It was discovered by JJ Reyes of Secunia Research and tested on Windows XP SP2 (fully patched) English, IE6 and IE7, PVCalendar.ocx version 10.0.0.17. It was written by e.b. and thanks to h.d.m. and the Metasploit crew.
Oreon is prone to a remote file-inclusion vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to execute arbitrary PHP code within the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.