header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

CSRF Asus RT-N66U Arbitrary Command Execution

The Asus RT-N66U is a home wireless router. Its web application has a CSRF vulnerability that allows an attacker to execute arbitrary commands on the target device. The parameter 'SystemCmd' in the URL causes the device to execute arbitrary commands. Console output can be observed by sending a GET request to http://192.168.1.1/cmdRet_check.htm after calling the URL. The URLs are protected with HTTP Basic Access Authentication. If a victim has logged in to the router recently, the exploit will work without further intervention. Otherwise, attackers can try supplying default credenitals in the URL.

Tenda W309R Configuration Enumeration without Authentication

Tenda Wireless Router W309R doesn't have proper authentication for the web application console. Though the application asks for password, it has poor cookie management which allows a user to login even without providing the password. Application uses cookie value 'admin' to access the private pages which reveals configuration details such as PPoE username, PPoE password, wireless authentication key, details of MAC addresses etc, in the source code.

ArticleSetup Multiple Vulnerabilities

Cross Site Scripting: An attacker can inject malicious JavaScript code into the search.php page of the vulnerable application. SQL Injection: An attacker can inject malicious SQL queries into the feed.php and search.php pages of the vulnerable application.

Posnic Stock Management System 1.02 Multiple Vulnerabilities

Multiple SQL Injection vulnerabilities were found in Posnic Stock Management System 1.02. These vulnerabilities can be exploited by malicious people to conduct SQL injection attacks. The vulnerabilities are located in the 'change_password.php', 'forget_pass.php', 'update_sales.php', 'update_customer_details.php', 'update_purchase.php', 'update_supplier.php', 'update_stock.php', 'update_payment.php', 'view_sales.php', 'view_customers.php', 'view_purchase.php', 'view_supplier.php', 'view_product.php' and 'view_payments.php' scripts. Input passed via the 'old_pass', 'name', 'sid', 'searchtxt' parameters to the scripts is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Hewlett-Packard 2620 Switch Series. Edit Admin Account – CSRF Vulnerability

This vulnerability allows an attacker to change the password of the admin account on the Hewlett-Packard 2620 Switch Series. The vulnerability exists due to insufficient validation of the HTTP request sent to the web server. An attacker can send a specially crafted HTTP request to the web server and change the password of the admin account.

Blast XPlayer Local Buffer Overflow PoC

This application is a music player application is very practical and simple. Easy to use and the capacity that is not too big only 5MB. with this application you can play music whenever you want to store in flashdisc and opened on the computer without having to install it first.

Piwigo 2.5.2 <= Cross Site Scripting

Piwigo is photo gallery software for the web, built by an active community of users and developers. An attacker can exploit this vulnerability by creating a new album, inserting a photo, and inserting malicious code into the 'Title', 'Author', 'Tags', and 'Description' fields. When the photo is viewed in the gallery, the malicious code will be executed.

Recent Exploits: