header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

ACE Stream Media 2.1 (acestream://) Format String Exploit PoC

Ace Stream Media (Ace Player HD) is prone to a remote format string vulnerability because the application fails to properly sanitize user-supplied input thru the URI using the 'acestream://' protocol before including it in the format-specifier argument of a formatted-printing function. A remote attacker may exploit this issue to execute arbitrary code with the privileges of the user running the affected application and/or cause memory address disclosure. Failed exploit attempts may cause denial-of-service (DoS) conditions.

Nisuta NS-WIR150NE, NS-WIR300N Wireless Routers Remote Management Web Interface Authentication Bypass Vulnerability

The Nisuta (www.nisuta.com) NS-WIR150NE and NS-WIR300N wireless routers provide a remote management web interface available both on the WAN (not enabled by default) and LAN interfaces (enabled by default). This remote management web interface requires a password. A remote attacker can bypass authentication and gain access to the remote management web interface, taking control of the device, without knowing the password.

Ofilter Player 1.1 (.wav) Integer Division by Zero

This vulnerability is an Integer Division by Zero vulnerability in Ofilter Player 1.1. It occurs when a specially crafted .wav file is opened in the application. This causes the application to crash due to an integer division by zero error. This can be exploited to execute arbitrary code by an attacker.

{D-Link DSL-2750U} CSRF Vulnerability

This router allows an attacker to bypass authentication and login to the setup page after that just make any settings and save or apply it and it's going to say 'wrong old password'. Don't worry just hit ok. Now the attacker is in the Router settings and can download the config file or whatever they want. The attacker can then easily make a new settings including a new login password.

Huawei Technologies du Mobile Broadband 16.0 Local Privilege Escalation

The application is vulnerable to an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (full) for the 'Everyone' and 'Users' group, for the 'du Mobile Broadband.exe' binary file. The files are installed in the 'du Mobile Broadband' directory which has the Everyone group assigned to it with full permissions making every single file inside vulnerable to change by any user on the affected machine. After you replace the binary with your rootkit, on reboot you get SYSTEM privileges.

Song Exporter v2.1.1 RS iOS – File Include Vulnerabilities

The vulnerability allows remote attackers to include local files and external webpages from the application context. The local file include web vulnerability is located in the `file` value of the `/export` POST method request. Remote attackers are able to inject own malicious script codes to the vulnerable file parameter value.

Synology DSM multiple directory traversal

Synology DiskStation Manager (DSM) is a Linux based operating system, used for the DiskStation and RackStation products. A directory traversal vulnerability was discovered in the FileBrowser components, which allows any authenticated user to access, create, delete, and modify system and configuration files. The only countermeasure implemented against this vulnerability is the check that the path starts with a valid shared folder, which can be bypassed by putting the '../' straight after. Vulnerable CGIs include /webapi/FileStation/html5_upload.cgi, /webapi/FileStation/file_delete.cgi, /webapi/FileStation/file_download.cgi, /webapi/FileStation/file_sharing.cgi, /webapi/FileStation/file_share.cgi, /webapi/FileStation/file_MVCP.cgi, and /webapi/FileStation/file_rename.cgi.

Firefox 5.0 – 15.0.1 __exposedProps__ XCS Code Execution

On versions of Firefox from 5.0 to 15.0.1, the InstallTrigger global, when given invalid input, would throw an exception that did not have an __exposedProps__ property set. By re-setting this property on the exception object's prototype, the chrome-based defineProperty method is made available. With the defineProperty method, functions belonging to window and document can be overriden with a function that gets called from chrome-privileged context. From here, another vulnerability in the crypto.generateCRMFRequest function is used to 'peek' into the context's private scope. Since the window does not have a chrome:// URL, the insecure parts of Components.classes are not available, so instead the AddonManager API is invoked to silently install a malicious plugin.

HP SiteScope issueSiebelCmd Remote Code Execution

This module exploits a code execution flaw in HP SiteScope. The vulnerability exists in the APISiteScopeImpl web service, specifically in the issueSiebelCmd method, which allows the user to execute arbitrary commands without authentication. This module has been tested successfully on HP SiteScope 11.20 over Windows 2003 SP2, Windows 2008 and CentOS 6.5.

Synology DiskStation Manager SLICEUPLOAD Remote Command Execution

This module exploits a vulnerability found in Synology DiskStation Manager (DSM) versions 4.x, which allows the execution of arbitrary commands under root privileges. The vulnerability is located in /webman/imageSelector.cgi, which allows to append arbitrary data to a given file using a so called SLICEUPLOAD functionality, which can be triggered by an unauthenticated user with a specially crafted HTTP request. This is exploited by this module to append the given commands to /redirect.cgi, which is a regular shell script file, and can be invoked with another HTTP request. Synology reported that the vulnerability has been fixed with versions 4.0-2259, 4.2-3243, and 4.3-3810 Update 1, respectively; the 4.1 branch remains vulnerable.

Recent Exploits: