This exploit is related to a Password Change Vulnerability in which an attacker can change the password of a system by exploiting a vulnerable CGI script. The attacker can use a perl script to send a GET request to the vulnerable CGI script with the new password as a parameter. The script will then change the password of the system.
The ASUS RT-AC66U contains the Broadcom ACSD Wireless binary that is vulnerable to multiple Buffer Overflow attacks. Multiple overflows exist in the following software: Broadcom acsd - Wireless Channel Service (autochannel¶m, autochannel&data, csscan&ifname commands)
The Rio-47100 by Galil is a small PLC with an internal RISC based processor. It communicates using ModBus, or Telnet over Ethernet as well as having a web server built in that allows a user to issue commands. Repeating a request in a single packet format can cause the PLC to crash.
Basic Forum is affected by multiple vulnerabilities, including multiple SQL injections, multiple cross-site scripting, and cross-site request forgery.
Easy Blog is affected by multiple vulnerabilities. The image upload function in add.php allows unrestricted file upload. An attacker may upload a shell gaining unauthorized access to the system. Additionally, there are multiple SQL injections and Cross-Site Scripting vulnerabilities present in the application.
Windu CMS suffers from a cross-site request forgery vulnerability. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Due to improper access restriction the FOSCAM FI8620 device [1] allows a remote attacker to browse and access arbitrary files from the following directories '/tmpfs/' and '/log/' without requiring authentication. This could allow a remote attacker to obtain valuable information such as access credentials, Wi-Fi configuration and other sensitive information in plain text.
Microsoft's DirectShow API is vulnerable to arbitrary memory overwrite when reading specially crafted GIF files. This vulnerability affects Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012.
Artweaver is prone to a security vulnerability when processing AWD files. This vulnerability could be exploited by a remote attacker to execute arbitrary code on the target machine by enticing Artweaver users to open a specially crafted file.
This module exploits a code execution flaw in VMware vCenter Chargeback Manager, where the ImageUploadServlet servlet allows unauthenticated file upload. The files are uploaded to the /cbmui/images/ web path, where JSP code execution is allowed. The module has been tested successfully on VMware vCenter Chargeback Manager 2.0.1 on Windows 2003 SP2.