The persistent input validation web vulnerability can be exploited by remote attackers with low privileged application user account and without user interaction. For demonstration or reproduce ... 1. Start the WiFi Camera Roll v1.2 iOS mobile web-application 2. Open the `index.html` file 3. Inject own malicious script codes to the `name` and `password` value 4. Execute the injected script code
It is possible to perform a privilege escalation attack due to a lack of permissions check in the group creation process. A malicious user could exploit this vulnerability to take control of every group (change name, description, avatar and settings). To exploit this vulnerability you have to follow these steps: 1) Create a cookie named bp_new_group_id=<id_of_victim_group> 2) Visit the url http://example.com/groups/create/step/group-details/ 3) Enjoy the power
Frontend Upload Wordpress Plugin is vulnerable to arbitrary file upload. An attacker can upload malicious files with php extension like c99.php, shell.gif.php, etc. and access them via http://localhost/wp-content/uploads/feuGT_uploads/feuGT_1790_43000000_948109840.php
The D-Link DSL-2750B's web interface (listening on tcp/ip port 80) is prone to CSRF vulnerabilities which allows to change router parameters. The proof-of-concept code includes an HTML page with an image tag that points to the vulnerable router's IP address.
ZTE ZXV10 W300 router contains hardcoded credentials that are useable for the telnet service on the device. The username is 'admin' and the password is 'XXXXairocon' where 'XXXX' is the last four characters of the device's MAC address. The MAC address is obtainable over SNMP with community string public.
This plugin shows advanced Informations about a user, such as last IP, User Agent, Browser and Operating System. The information will be shown in a user profile and visible only for people who are able to see the adminoptions on user profiles. Proof of Concept: 1. Create a user account. 2. Change your user-agent to 'Mozilla<script>alert(1)</script>'. 3. Login and then... logout. The script will be executed whenever the administrator view your profile.
The vulnerability exists due to a boundary error when handling requests with an overly long URI. This can be exploited to cause a stack-based buffer overflow by sending a specially crafted HTTP request with an overly long URI to the affected server.
The vulnerability exists due to insufficient validation of "_position_down_id" HTTP POST parameter passed to "/dg-admin/index.php" script. A remote attacker with access to administrative interface can execute arbitrary SQL commands in application's database. This vulnerability however can be exploited by a remote unauthenticated user via CSRF vector.
Standard Ctera User can define a particular “description” for a ProjectFolder that cause javascript code execution and HTML injection. User can forge particular description on Project Folder that permit XSS, HTML Injection (add of link, images, button ecc). As the project folder can be shared with different users that vulnerability permit the grabbing of sessions cookies.
The Serendipity 1.7.5 backend is prone to multiple security vulnerabilities. Stored-XSS can be executed by setting the 'Real name' field to a malicious script. SQL-Injection can be executed by sending a malicious payload to the 'serendipity[install_plugin]' parameter. Reflected XSS_1, Reflected XSS_2 and Reflected XSS_3 can be executed by sending malicious payloads to the 'serendipity[install_plugin]', 'serendipity[id]' and 'serendipity[timestamp]' parameters respectively.