The username and password of the database may be obtained trough the 'application.ini' file.
A stack based buffer overflow vulnerability exists in Up.Time Agent 5.0.1 (i386). This exploit will create a bind shell running on port 4444 on the targeted host.
Input passed via the 'lang' POST parameter in the newsletter plugin is not properly sanitised before being used to construct a XPath query for XML data. This can be exploited to manipulate XPath queries by injecting arbitrary XPath code.
This exploit allows an attacker to upload a file to the vulnerable server. The exploit is written in PHP and takes two parameters, the URL of the vulnerable server and the file to be uploaded. The exploit then sends a POST request to the server with the file and the fileId parameter set to the name of the file. If the server responds with a message containing 'UPLOAD_SUCCESS', the exploit is successful.
This exploit is a rip of the original exploit which works most of the times. It is a script which requires Ruby 1.9.x and Gems: origami, metasm. It is supported on Adobe Reader Versions 11.0.1, 11.0.0, 10.1.5, 10.1.4, 10.1.3, 10.1.2, 10.1, 9.5 and tested on Windows 7 (32 bit), Windows 7 (64 bit) and Windows XP. It is used to inject a PE executable into a PDF file.
This module exploits a vulnerability on Microsoft Silverlight. The vulnerability exists on the Initialize() method from System.Windows.Browser.ScriptObject, which access memory in an unsafe manner. Since it is accessible for untrusted code (user controlled) it's possible to dereference arbitrary memory which easily leverages to arbitrary code execution. In order to bypass DEP/ASLR a second vulnerability is used, in the public WriteableBitmap class from System.Windows.dll. This module has been tested successfully on IE6 - IE10, Windows XP SP3 / Windows 7 SP1 on both x32 and x64 architectures.
A vulnerability in the WordPress dzs-videogallery plugin allows an attacker to upload arbitrary files to the server. The vulnerable file is upload.php, which is located in the /wp-content/plugins/dzs-videogallery/admin/dzsuploader/ directory. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the upload.php file. This will allow the attacker to upload arbitrary files to the server, which can then be used to execute arbitrary code.
This module exploits a Perl code injection on NETGEAR ReadyNAS 4.2.23 and 4.1.11. The vulnerability exists on the web fronted, specifically on the np_handler.pl component, due to the insecure usage of the eval() perl function. This module has been tested successfully on a NETGEAR ReadyNAS 4.2.23 Firmware emulated environment, not on real hardware.
This module exploits an arbitrary file upload vulnerability in DesktopCentral 8.0.0 below build 80293. A malicious user can upload a JSP file into the web root without authentication, leading to arbitrary code execution.
A denial of service vulnerability exists in Static Http Server 1.0 due to improper handling of maliciously crafted requests. An attacker can send a specially crafted request to the vulnerable server, resulting in a denial of service condition.