It is possible to bypass authentication within Moab in order to impersonate and run commands/operations as arbitrary users. The issue is believed to affect all versions of Moab prior to versions 7.2.9 and Moab 8.
Two SQL injection vulnerabilities have been found and confirmed within the software as an authenticated user. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database. The following URLs and parameters have been confirmed to suffer from Multiple SQL injections: Vulnerability 1 (Fixed in commit #7a09973 in official repository) and Vulnerability 2 (Fixed in patches after commit #7a09973 in official repository)
PhpCompta 6.7.1-2 does not validate the syntax of the commands when processing backup requests from users. It is possible to abuse the 'd' parameter to inject additional parameters that will then be passed via the php passthru() function to create a backup file, which will subsequently be executed.
This exploit listens for clients performing a DISCOVER, a later version will exploit periodic REQUESTs, which can sometimes be prompted by causing IP conflicts. Once a broadcast DISCOVER packet has been detected, the XID, MAC and requested IP are pulled from the pack and a corresponding OFFER and ACK are generated and pushed out. The client is expected to reject the offer in preference of their known DHCP server, but will still process the packet, triggering the vulnerability.
Add a product to a customer basket with an image tag and without any verification.
TeamSpeak Client v3.0.14 is vulnerable to buffer overflow attacks. Sending a specially crafted message to the chat/server tab of a channel/server can cause a mass crash of the client and the users connected with a vulnerable version. The exploit code must be sent into the chat/server tab for a channel/server crash effect.
The Vulnerability Laboratory Research Team discovered two persistent vulnerabilities in the official All in One Security & Firewall v3.8.3 Wordpress Plugin. The vulnerability allows remote attackers to inject own malicious script codes to the application-side of the vulnerable plugin. The vulnerability is located in the `aiowps_process_login_form_post_request` function with the `aiowps_login_form_post_request` parameter of the `/wp-content/plugins/all-in-one-wp-security-and-firewall/lib/wp-security-process.php` file.
The latest HTTP File Server (2.3c and maybe prior too) was found to be vulnerable to a remote command execution in the file comment features, because the application did not properly validate uft-8 broken byte representation, in fact during parsing program won't notice that there are multiple invalid representation and when they are printed into the page will get replaced with one of these characters " { . | } " causing a macro to be executed.
It is possible to shutdown/reboot a server running openfiler and cause denial of service via CSRF due to missing session tokens.
A local file include web vulnerability has been discovered in the official Golden Soft Photo/Foto Uebertraeger v3.0 iOS mobile application. The local file include web vulnerability allows remote attackers to unauthorized include local file/path requests or system specific path commands to compromise the mobile web-application.