The web server (DMCRUIS/0.1) on port TCP/5600 is crashing by sending a long HTTP GET request. Tested successfully on Samsung PS50C7700 plasma TV.
The Vulnerability Laboratory Research Team discovered a command injection and file include (arbitrary file upload) vulnerability in the Photo Server 2.0 application (Apple iOS - iPad & iPhone). The vulnerability allows to inject loccal system commands and paths to compromise the application or connected service. The vulnerability is located in the `upload` value of the `upload.php` file. Remote attackers are able to inject own malicious commands and paths to compromise the application or connected service. A local file include web vulnerability is detected in the Photo Server 2.0 application (Apple iOS - iPad & iPhone). The vulnerability allows to inject local file requests to compromise the application or connected service. The vulnerability is located in the `upload` value of the `upload.php` file. Remote attackers are able to inject own malicious files to compromise the application or connected service.
SuperPlayer3500 is vulnerable to a local stack based buffer overflow. The vulnerability is caused due to a boundary error when handling specially crafted .M3U files. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted .M3U file. Successful exploitation may allow execution of arbitrary code.
This module exploits a vulnerability found in Apple Quicktime. The flaw is triggered when Quicktime fails to properly handle the data length for certain atoms such as 'rdrf' or 'dref' in the Alis record, which may result a buffer overflow by loading a specially crafted .mov file, and allows arbitrary code execution under the context of the user.
VbsEdit 5.9.3 is vulnerable to a buffer overflow vulnerability when handling .smi files. An attacker can craft a malicious .smi file with a large amount of data, which when opened in VbsEdit 5.9.3, will cause a buffer overflow and potentially allow for arbitrary code execution.
The MLM Script is vulnerable to SQL Injection and XSS attacks. An attacker can inject malicious SQL queries into the vulnerable parameters of the application, such as the 'prdid' and 'uid' parameters of the productview.php page, and the 'email' parameter of the regcheck_email.php page. An attacker can also inject malicious JavaScript code into the 'email' parameter of the regcheck_email.php page.
This module exploits a buffer overflow found in the USER command of PCMan's FTPD. It sends a malicious USER command with a large number of 'A' characters followed by the return address and payload encoded in the command.
The vulnerability allows an remote attacker to inject/execute own sql commands on the affected application dbms. The vulnerability is located in the `user` value of the `/admin/login.php` file. Remote attackers are able to inject own sql commands to compromise the application dbms. The request method to inject is POST and the attack vector is located on the application-side of the service. The security risk of the sql injection vulnerability is estimated as high with a cvss (common vulnerability scoring system) count of 8.6. Exploitation of the sql injection vulnerability requires no user interaction or privileged application user account. Successful exploitation of the vulnerability results in dbms, web-server and application compromise.
The Barracuda Web Filter is vulnerable to multiple vulnerabilities, including a Cross-Site Scripting (XSS) vulnerability, a Cross-Site Request Forgery (CSRF) vulnerability, and an authentication bypass vulnerability. The XSS vulnerability allows an attacker to inject malicious JavaScript code into the web interface of the Barracuda Web Filter. The CSRF vulnerability allows an attacker to perform malicious actions on behalf of a legitimate user. The authentication bypass vulnerability allows an attacker to bypass authentication and gain access to the web interface of the Barracuda Web Filter.
An attacker can execute malicious content using a comment form on the article.php file. The malicious content could be either JavaScript code, but may also include HTML, Flash etc. The code is executed over form where 'Name' field is actual vulnerability. The code is called through POST action and the function 'comment_name()' is the actual result of the exploit.