A vulnerability exists in DMXReady Billboard Manager version 1.1 and earlier which allows an attacker to upload arbitrary files to the server. This is due to a lack of proper input validation and authentication checks in the upload_document.asp script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malicious file attached to the upload_document.asp script. This can allow an attacker to upload malicious files to the server and execute arbitrary code.
A vulnerability in DMXReady SDK version 1.1 and below allows an attacker to download arbitrary files from the target server. This is done by sending a specially crafted HTTP request to the download_link.asp script, which contains the path to the file to be downloaded. The file is then sent to the attacker in the response body.
A remote SQL injection vulnerability exists in DMXReady Secure Document Library version 1.1. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. This can allow the attacker to gain access to the application's database and potentially execute arbitrary code.
If 'preview' from GET is provided, we can include it just bypassing a stupid cheek. file_exists('./skin/$skin_temp/config.php) <-- this cheek is stupid, becouse when we set a value to $skin_temp , if we set a local file with a directory trasversal it's obvious that the file exists, so it will be included.
This exploit allows a remote attacker to execute arbitrary code on vulnerable installations of Oracle TimesTen. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the 'evtdump' parameter. By supplying a specially crafted format string, an attacker can cause a stack-based buffer overflow and execute arbitrary code.
A vulnerability in DMXReady Registration Manager version 1.1 allows an attacker to remotely change the contents of the application. This is done by exploiting the permissions of the add_category.asp page, which allows an attacker to update, delete, and insert categories and subcategories.
A vulnerability in DMXReady Photo Gallery Manager <= 1.1 allows an attacker to remotely change the contents of the application. This is due to the lack of authentication when accessing the add_category.asp page, which allows an attacker to add, update, delete, and insert categories and subcategories, as well as upload images.
A vulnerability in DMXReady PayPal Store Manager version 1.1 allows an attacker to remotely change the contents of the website. This is due to the lack of authentication in the CategoryManager/list.asp page, which allows an attacker to update, delete, insert categories and subcategories, upload images, etc.
The Oracle January 2009 Critical Patch Update fixes a vulnerability which allows a remote preauthenticated attacker to execute arbitrary code in the context of the user running the web server of Oracle Secure Backup. In Windows environments, the vulnerability allows execution of arbitrary code as SYSTEM. In Unix and GNU/Linux environments, however, just as a normal user (oracle usually).
This exploit is used to gain remote command execution on a vulnerable Phosheezy application. It first grabs the admin password from the config/password file, then logs in as an administrator and edits the template to create a Remote Command Execution vulnerability. It then connects to the server and sends a POST request to the shell.php file to execute the command.