header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Exploit Http DoS Request for SCADA ATTACK Elipse 3

Mauro Risonho de Paula Assumpção aka firebits discovered a Denial of Service (DoS) vulnerability in Elipse 3. The vulnerability is caused due to an error in the application when handling a specially crafted HTTP request and can be exploited to cause a hard lock Dll crash in Windows 2003 SP2 with 20 requests connections per second. This vulnerability is identified as CVE-2014-8652.

WordPress db-backup plugin File Download Vulnerability

A vulnerability in the Wordpress db-backup plugin allows an attacker to download any file from the server by accessing the download.php file with the file path as a parameter. This vulnerability affects all versions of the plugin prior to version 2.2.2.

Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 (.wax) SEH Buffer Overflow

Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 is vulnerable to a SEH buffer overflow vulnerability. An attacker can exploit this vulnerability by crafting a malicious .wax file and sending it to the victim. When the victim opens the malicious file, the attacker can execute arbitrary code on the victim's system.

CVE-2014-8768 tcpdump denial of service in verbose mode using malformed Geonet payload

It was found out that malformed network traffic (Geonet-based) can lead to an application crash (denial of service) if verbose output of tcpdump monitoring the network is used. The application decoder for the geonet protocol fails to perform external input validation and performs insufficient checking on length computations leading to an unsafe decrement and underflow in the function geonet_print(netdissect_options *ndo, const u_char *eth, const u_char *bp, u_int length). The affected variable is length which is later on used to print a memory chunk which eventually leads to a segfault.

Advantech EKI-6340 Command Injection

The Advantech EKI-6340 series are wireless Mesh AP for outdoor deployment. With self-healing and self-forming capabilities, the wireless network is free from interruption even part of Mesh nodes failed. It's especially critical to infrastructures where wired solutions are hard to deploy. This Mesh network covers growing rich data demands such as video security, surveillance and entertainment. Advantech EKI-6340 series is vulnerable to a OS Command Injection, which can be exploited by remote attackers to execute arbitrary code and commands, by using a non privileged user against a vulnerable CGI file.

Recent Exploits: