header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WordPress appointment-booking-calendar <=1.1.23 - Shortcode SQL injection

A SQL injection flaw was discovered within the latest WordPress appointment-booking-calendar plugin version 1.1.20. The flaw allows an authenticated user with editor, author, or administrator privileges to exploit this vulnerability by adding crafted shortcodes on a page or post, leading to potential compromise of the entire web server.

Xdh / LinuxNet Perlbot / fBot IRC Bot Remote Code Execution

This module allows remote command execution on an IRC Bot developed by xdh. This perl bot was caught by Conor Patrick with his shellshock honeypot server and is categorized by Markus Zanke as an fBot (Fire & Forget - DDoS Bot). Matt Thayer also found this script which has a description of LinuxNet perlbot. The bot answers only based on the servername and nickname in the IRC message which is configured on the perl script thus you need to be an operator on the IRC network to spoof it and in order to exploit this bot or have at least the same ip to the config.

BarCodeWiz ActiveX Control 2.52 (BarcodeWiz.dll) Stack Overflow SEH Overwrite Exploit

This exploit takes advantage of a stack overflow vulnerability in the BarCodeWiz ActiveX Control 2.52 (BarcodeWiz.dll). By exploiting this vulnerability, an attacker can overwrite the Structured Exception Handling (SEH) chain, potentially allowing for arbitrary code execution. This exploit includes a shellcode that opens the Windows Calculator application on Windows 2000.

NoAh 0.9 The PHP Content Architect <= Remote File Inclusion Vulnerability

The vulnerability exists in the 'mfa_theme.php' file of the NoAh PHP Content Architect. An attacker can exploit this vulnerability by including a remote file through the 'tpls[1]' parameter in the URL. This can lead to remote code execution on the affected system.

Recent Exploits: