header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Zabbix 2.0.8 SQL Injection and Remote Code Execution

This module exploits an unauthenticated SQL injection vulnerability affecting Zabbix versions 2.0.8 and lower. The SQL injection issue can be abused in order to retrieve an active session ID. If an administrator level user is identified, remote code execution can be gained by uploading and executing remote scripts via the 'scripts_exec.php' file.

Dolibarr 3.4.0 SQLi

This exploit allows an attacker to inject malicious code into the Dolibarr 3.4.0 web application. The malicious code is injected into the 'exportcsv.php' file, which is then used to execute arbitrary commands on the server. The exploit was discovered by drone (@dronesec) in 2013 and affects Dolibarr versions 3.4.0 and below. The vulnerability was patched in version 3.4.1.

Dexs PM System – Authenticated Persistent Cross Site Scripting Vulnerability

Dexs PM System suffers from a persistent Cross-Site Scripting vulnerability when sending a message as an authenticated user. An account of at least subscriber status is requested to exploit this vulnerability. This vulnerability exists due to a lack of input validation and output sanitization of the subject paramater.

Aladdin Knowledge Systems Ltd. PrivAgent ActiveX Control Overflow

A buffer overflow vulnerability exists in Aladdin Knowledge Systems Ltd. PrivAgent ActiveX Control due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by enticing a victim to visit a malicious web page containing a specially crafted HTML that when loaded, will trigger the overflow and execute arbitrary code on the victim's system.

VMware Hyperic HQ Groovy Script-Console Java Execution

This module uses the VMware Hyperic HQ Groovy script console to execute OS commands using Java. Valid credentials for an application administrator user account are required. This module has been tested successfully with Hyperic HQ 4.6.6 on Windows 2003 SP2 and Ubuntu 10.04 systems.

Fork Bomb Attack

The fork bomb attack is a type of denial of service attack that works by creating multiple processes that consume all available system resources. This attack was discovered in 2011 and was assigned the CVE-2011-3918. It was found to be exploitable on Android devices, and the exploit code was released in 2012. The exploit code consists of two parts: a BootReceiver.java and a ServiceDOS.java. The BootReceiver.java is responsible for starting the ServiceDOS.java, which is responsible for creating multiple processes that consume all available system resources.

StatusNet/Laconica <= 0.7.4, <= 0.8.2, <= 0.9.0beta3 - arbitrary file reading

StatusNet/Laconica versions 0.7.4, 0.8.2, and 0.9.0beta3 are vulnerable to arbitrary file reading. The vulnerability exists due to a lack of input validation on the user-supplied parameter 'title' in the 'actions/doc.php' file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to read arbitrary files from the server.

Internet Haut Debit Mobile Buffer Overflow SEH

A buffer overflow vulnerability exists in Internet Haut Debit Mobile PCW_MATMARV1.0.0B03. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This can be exploited by sending a specially crafted request to the vulnerable application. This vulnerability is due to a boundary error when handling user-supplied input. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.

ALLPlayer Local Buffer Overflow PoC UNICODE

A buffer overflow vulnerability exists in ALLPlayer 5.6.2, which could allow an attacker to execute arbitrary code. The vulnerability is caused by a boundary error when handling a specially crafted .m3u file. By persuading a victim to open a specially crafted .m3u file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Recent Exploits: