header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Password Change Vulnerability

This exploit is related to a Password Change Vulnerability in which an attacker can change the password of a system by exploiting a vulnerable CGI script. The attacker can use a perl script to send a GET request to the vulnerable CGI script with the new password as a parameter. The script will then change the password of the system.

ASUS RT-AC66U Remote Root Shell Exploit – acsd param command

The ASUS RT-AC66U contains the Broadcom ACSD Wireless binary that is vulnerable to multiple Buffer Overflow attacks. Multiple overflows exist in the following software: Broadcom acsd - Wireless Channel Service (autochannel&param, autochannel&data, csscan&ifname commands)

Galil RIO-47100

The Rio-47100 by Galil is a small PLC with an internal RISC based processor. It communicates using ModBus, or Telnet over Ethernet as well as having a web server built in that allows a user to issue commands. Repeating a request in a single packet format can cause the PLC to crash.

Easy Blog by JM LLC – Multiple Vulnerabilities

Easy Blog is affected by multiple vulnerabilities. The image upload function in add.php allows unrestricted file upload. An attacker may upload a shell gaining unauthorized access to the system. Additionally, there are multiple SQL injections and Cross-Site Scripting vulnerabilities present in the application.

Windu CMS 2.2 CSRF Add Admin Exploit

Windu CMS suffers from a cross-site request forgery vulnerability. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

FOSCAM IP-Cameras Improper Access Restrictions

Due to improper access restriction the FOSCAM FI8620 device [1] allows a remote attacker to browse and access arbitrary files from the following directories '/tmpfs/' and '/log/' without requiring authentication. This could allow a remote attacker to obtain valuable information such as access credentials, Wi-Fi configuration and other sensitive information in plain text.

DirectShow Arbitrary Memory Overwrite Vulnerability

Microsoft's DirectShow API is vulnerable to arbitrary memory overwrite when reading specially crafted GIF files. This vulnerability affects Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012.

VMware vCenter Chargeback Manager ImageUploadServlet Arbitrary File Upload

This module exploits a code execution flaw in VMware vCenter Chargeback Manager, where the ImageUploadServlet servlet allows unauthenticated file upload. The files are uploaded to the /cbmui/images/ web path, where JSP code execution is allowed. The module has been tested successfully on VMware vCenter Chargeback Manager 2.0.1 on Windows 2003 SP2.

Recent Exploits: