A vulnerability exists in Macrovision FlexNet isusweb.dll which allows remote attackers to execute arbitrary code via the DownloadAndExecute method. This can be exploited by a malicious website to execute arbitrary code on a vulnerable system by using the ActiveX control in Internet Explorer.
The bug will allow an attacker to accept sent comments in the articles, erase comments and delete articles. The vulnerability is caused by the lack of proper input validation in the comment_accepter.php, comment_refuser.php and article_suppr.php scripts, which allows an attacker to inject malicious SQL queries. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL queries to the vulnerable scripts.
Cisco Systems VPN Client IPSec Driver is vulnerable to a local kernel system pool corruption. Specifying an input buffer size less-than 8+31-bytes results in the local kernel non-paged pool (METHOD_BUFFERED) being corrupted with uninitialised (dangling) kernel stack memory via an inline memcpy.
RichStrong CMS is vulnerable to a remote SQL injection vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the database, such as user credentials and other sensitive data.
This exploit uses the insecure methods of Macrovision FlexNet DownloadManager to download and execute a malicious file from a remote server. The malicious file is downloaded to the startup folder of the system and is executed when the system is restarted.
Xforum 1.4 is vulnerable to a remote SQL injection vulnerability. An attacker can exploit this vulnerability to gain access to the database and extract sensitive information such as usernames, passwords, and emails. The vulnerability exists in the liretopic.php file, where the application is not properly sanitizing user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL code to the vulnerable application.
This exploit allows an attacker to extract usernames and hashes from a vulnerable version of xchat 2.0.5. The exploit is a PoC and is done by sending a malicious SQL query to the target host.
This exploit is a proof-of-concept for a remote buffer overflow vulnerability in Quicktime Player 7.3.1.70. The vulnerability is triggered when a maliciously crafted RTSP packet is sent to the vulnerable application. This can lead to arbitrary code execution.
Agares PhpAutoVideo 2.21 is vulnerable to a remote SQL injection vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to gain access to the application's database and potentially execute arbitrary code.
Binn SBuilder is vulnerable to a Blind Sql Injection vulnerability. This vulnerability can be exploited by sending a maliciously crafted HTTP request to the vulnerable application. An attacker can use this vulnerability to extract sensitive information from the database, such as usernames and passwords. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'nid' parameter of the 'full_text.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL code to the vulnerable application. The malicious SQL code can be used to extract sensitive information from the database, such as usernames and passwords.