header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Dell SonicWall GMS v7.2.x – Persistent Web Vulnerability

Dell SonicWall GMS v7.2.x is prone to a persistent web vulnerability. The vulnerability allows remote attackers to inject malicious persistent script codes to the application-side of the vulnerable module. The persistent script code will be executed in the browser of the user if the vulnerable module is visited. The vulnerability is located in the `name` value of the `/gms/login.jsp` module. Remote attackers are able to inject own malicious persistent script codes to the vulnerable `name` value of the `/gms/login.jsp` module. The persistent attack vector is located on the application-side and the request method to inject is POST. The execution of the persistent script code occurs in the main page of the vulnerable module. The security risk of the persistent web vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 3.0. Exploitation of the persistent web vulnerability requires no user interaction or privileged web-application user account. Successful exploitation of the vulnerability results in session hijacking, persistent phishing attacks, persistent external redirects and persistent malicious manipulation of affected or connected module context.

Axway Secure Transport 5.1 SP2 Arbitary File Upload via CSRF

It is possible to conduct CSRF on a user to upload arbitary files on the Axway Secure Transport server. This is due to the lack of anti-CSRF tokens in the web API. An adversary may exploit this to upload webshells for further attacks.

Feng Office Community Edition Cross-Site Scripting Vulnerability

Feng Office Community Edition is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

iBackup <= 10.0.0.32 Local Privilege Escalation

There are weak permissions for IBackupWindows default installation where everyone is allowed to change the ib_service.exe with an executable of their choice. When the service restarts or the system reboots the attacker payload will execute on the system with SYSTEM privileges.

iFunBox Free v1.1 iOS – File Include Vulnerability

A local file include web vulnerability has been discovered in the official iFunBox Free v1.1 iOS mobile web-application. The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific path commands to compromise the mobile web-application. The web vulnerability is located in the `filename` value of the `upload` module. Remote attackers are able to inject own files with malicious `filename` values in the `upload` POST method request to compromise the mobile web-application.

Joomla Akeeba Kickstart Unserialize Remote Code Execution

This module exploits a vulnerability found in Joomla! through 2.5.25, 3.2.5 and earlier 3.x versions and 3.3.0 through 3.3.4 versions. The vulnerability affects the Akeeba component, which is responsible for Joomla! updates. Nevertheless it is worth to note that this vulnerability is only exploitable during the update of the Joomla! CMS.

Linux PolicyKit Race Condition Privilege Escalation

A race condition flaw was found in the PolicyKit pkexec utility and polkitd daemon. A local user could use this flaw to appear as a privileged user to pkexec, allowing them to execute arbitrary commands as root by running those commands with pkexec. Those vulnerable include RHEL6 prior to polkit-0.96-2.el6_0.1 and Ubuntu libpolkit-backend-1 prior to 0.96-2ubuntu1.1 (10.10) 0.96-2ubuntu0.1 (10.04 LTS) and 0.94-1ubuntu1.1 (9.10)

Recent Exploits: