header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Multiple SQL Injection Vulnerabilities in SelectSurvey.net

SelectSurvey.net is a web-based survey application written in ASP.net and C#. It is vulnerable to multiple SQL injection attacks, both authenticated and unauthenticated. The authenticated vulnerability resides within the file upload script, as the parameters are not sanitized prior to being placed into the SQL query. ClassApps had previously listed 'SQL injection protection' as a feature and did have several functions in place to attempt to prevent such attacks but due to using a 'blacklisting' approach, it is possible to circumvent these functions. These functions are used elsewhere throughout the application to protect GET request variables but are not sufficient. Only this specific version of the application has been tested but it is highly likely these vulnerabilities exist within prior versions. It has not been confirmed that these vulnerabilities are fixed. The vendor stated that they would be fixed in this new release however, they do not allow download of the code unless you are a customer so fixes have not been verified.

Stored XSS in Livefyre LiveComments Plugin

This plugin requires user to be signed in via livefyre account to post comments. Users have the option to upload pictures in comments. This feature can be easily abused. Using an intercepting proxy (e.g. Burp Suite), the name variable can be edited to send an XSS payload while uploading a picture (payload used : "><img src=x onerror=prompt(1337)>). When the comment is posted, the image will be successfully uploaded, which leads to XSS due to an unsanitized field.

USB&WiFi Flash Drive 1.3 iOS – Code Execution Vulnerability

A remote code execution web vulnerability has been discovered in the official USB & Wi-Fi Flash Drive v1.3 iOS mobile web-application. The vulnerability allows remote attackers to execute own system (device) specific codes to compermise the application or device. The vulnerability is located in the `file` value of the `upload` POST method request. Remote attackers are able to inject own malicious codes to the vulnerable `file` value of the `upload` POST method request.

WordPress Slideshow Gallery 1.4.6 Shell Upload Exploit

WordPress Slideshow Gallery plugin version 1.4.6 suffers from a remote shell upload vulnerability (CVE-2014-5460). The vulnerability allows an attacker to upload a malicious shell file to the vulnerable server. The exploit requires the user to have enabled user management slide and python's httplib2 lib installed.

ZTE ZXDSL-931VII Unauthenticated Configuration Dump

An attacker can exploit this vulnerability by accessing the router's IP address and downloading the _config.bin file. The attacker can then use a python script to decompress the file and gain access to the configuration.

CSRF vulnerabilities in CacheGuard-OS v5.7.7

A CSRF vulnerability has been detected in CacheGuard in '/gui/password-wadmin.apl'. The application does not validate the parameter any csrf_token '/gui/password-wadmin.apl'. This allows attackers to modify settings or change password of user administrator in CacheGuard, because these functions are not protected by CSRF-Tokens.

ManageEngine Eventlog Analyzer Arbitrary File Upload

This module exploits a file upload vulnerability in ManageEngine Eventlog Analyzer. The vulnerability exists in the agentUpload servlet which accepts unauthenticated file uploads and handles zip file contents in a insecure way. By combining both weaknesses a remote attacker can achieve remote code execution. This module has been tested successfully on versions v7.0 - v9.9 b9002 in Windows and Linux. Versions between 7.0 and < 8.1 are only exploitable via EAR deployment in the JBoss server, while versions 8.1+ are only exploitable via a JSP upload.

Recent Exploits: