header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WiFi Camera Roll v1.2 iOS – Multiple Web Vulnerabilities

The persistent input validation web vulnerability can be exploited by remote attackers with low privileged application user account and without user interaction. For demonstration or reproduce ... 1. Start the WiFi Camera Roll v1.2 iOS mobile web-application 2. Open the `index.html` file 3. Inject own malicious script codes to the `name` and `password` value 4. Execute the injected script code

WordPress plugin Buddypress <= 1.9.1 privilege escalation

It is possible to perform a privilege escalation attack due to a lack of permissions check in the group creation process. A malicious user could exploit this vulnerability to take control of every group (change name, description, avatar and settings). To exploit this vulnerability you have to follow these steps: 1) Create a cookie named bp_new_group_id=<id_of_victim_group> 2) Visit the url http://example.com/groups/create/step/group-details/ 3) Enjoy the power

Frontend Upload WordPress Plugin – File Arbitrary Upload

Frontend Upload Wordpress Plugin is vulnerable to arbitrary file upload. An attacker can upload malicious files with php extension like c99.php, shell.gif.php, etc. and access them via http://localhost/wp-content/uploads/feuGT_uploads/feuGT_1790_43000000_948109840.php

D-Link DSL-2750B (ADSL Router) CSRF Vulnerability

The D-Link DSL-2750B's web interface (listening on tcp/ip port 80) is prone to CSRF vulnerabilities which allows to change router parameters. The proof-of-concept code includes an HTML page with an image tag that points to the vulnerable router's IP address.

ZTE ZXV10 W300 router contains hardcoded credentials

ZTE ZXV10 W300 router contains hardcoded credentials that are useable for the telnet service on the device. The username is 'admin' and the password is 'XXXXairocon' where 'XXXX' is the last four characters of the device's MAC address. The MAC address is obtainable over SNMP with community string public.

Extended Useradmininfo MyBB Plugin 1.2.1 – Cross Site Scripting

This plugin shows advanced Informations about a user, such as last IP, User Agent, Browser and Operating System. The information will be shown in a user profile and visible only for people who are able to see the adminoptions on user profiles. Proof of Concept: 1. Create a user account. 2. Change your user-agent to 'Mozilla<script>alert(1)</script>'. 3. Login and then... logout. The script will be executed whenever the administrator view your profile.

SQL Injection in doorGets CMS

The vulnerability exists due to insufficient validation of "_position_down_id" HTTP POST parameter passed to "/dg-admin/index.php" script. A remote attacker with access to administrative interface can execute arbitrary SQL commands in application's database. This vulnerability however can be exploited by a remote unauthenticated user via CSRF vector.

CTERA Project Folders – Stored XSS

Standard Ctera User can define a particular “description” for a ProjectFolder that cause javascript code execution and HTML injection. User can forge particular description on Project Folder that permit XSS, HTML Injection (add of link, images, button ecc). As the project folder can be shared with different users that vulnerability permit the grabbing of sessions cookies.

Serendipity 1.7.5 (Backend) – Multiple security vulnerabilities

The Serendipity 1.7.5 backend is prone to multiple security vulnerabilities. Stored-XSS can be executed by setting the 'Real name' field to a malicious script. SQL-Injection can be executed by sending a malicious payload to the 'serendipity[install_plugin]' parameter. Reflected XSS_1, Reflected XSS_2 and Reflected XSS_3 can be executed by sending malicious payloads to the 'serendipity[install_plugin]', 'serendipity[id]' and 'serendipity[timestamp]' parameters respectively.

Recent Exploits: