WordPress Gallery Objects 0.4 is vulnerable to SQL injection. An attacker can exploit this vulnerability to inject malicious SQL queries in the application, allowing them to bypass authentication, access, modify and delete data in the back-end database.
Argument for GET method is vulnerable to a buffer overflow. Analyzed on: D-Link: DSL2750U, DSL2740U, NetGear: WGR614, MR-ADSL-DG834. Disassembly in MIPS of vulnerable flow: sub_4067CC.
Omeka version 2.2 suffers from a cross-site request forgery and a stored XSS vulnerability. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site. Input passed to the 'api_key_label' POST parameter is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
This exploit allows an attacker to execute arbitrary code on the vulnerable system by using the Browserify library. The exploit works by encoding the malicious code in the form of a string and then using the String.fromCharCode() function to execute it. The malicious code can be used to execute arbitrary commands on the system, such as 'uptime' and 'id' to get system information.
Multiple stored XSS vulnerabilities exist in Bilboplanet application when creating and updating tribes, adding tags, and in parameters user_id and fullname.
The WebView class and use of the WebView.addJavascriptInterface method has vulnerability which cause remote code in html page run in android device. A proof of concept is provided in the text.
Different D-Link Routers are vulnerable to OS command injection via UPnP Multicast requests. This module has been tested on DIR-300 and DIR-645 devices. Zachary Cutlip has initially reported the DIR-815 vulnerable. Probably there are other devices also affected.
This module exploits an anonymous remote code execution vulnerability on different D-Link devices. The vulnerability is an stack based buffer overflow in the my_cgi.cgi component, when handling specially crafted POST HTTP requests addresses to the /common/info.cgi handler. This module has been successfully tested on D-Link DSP-W215 in an emulated environment.
Aerohive version 5.1r5 through 6.1r5 contain two vulnerabilities, one reflective XSS vulnerability and a limited local file inclusion vulnerability (I was only able to view source from one specific folder, maybe you can leverage this further). It's possible earlier version are affected, I was only able to review 5.1r5 briefly, the vendor indicated other version up to 6.1r5 are vulnerable as well.
Private Tunnel application suffers from an unquoted search path issue impacting the Core Service 'ptservice' service for Windows deployed as part of PrivateTunnel bundle. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.