Multiple persistent input validatino web vulnerabilities are detected in the DELL packetTrap PSA v7.1 web-application. The vulnerability allows remote attackers to inject own malicious script codes to the application-side of the vulnerable module. The persistent vulnerabilities are located in the `/psa/` directory of the web-application. Remote attackers are able to inject malicious script codes to the vulnerable `name` and `description` parameters of the `/psa/add_edit_service.php` module. The execution of the malicious script code occurs in the `/psa/service_list.php` module.
Multiple persistent input validaiton web vulnerabilities are detected in the DELL PacketTrap 6.6.23938 MSP RMM Software. The vulnerability allows remote attackers to implement/inject malicious script code on the application-side (persistent). The vulnerabilities are located in the `name` and `description` value of the `add/edit` module. Remote attackers are able to inject own malicious persistent script codes to the vulnerable `name` and `description` values. The request method to inject is POST and the attack vector is located on the application-side.
Directory traversal vulnerabilities occur when user input is used in the construction of a filename or directory path which is subsequently used in some system function. If the input is not correctly validated or directory permissions not correctly set, it may be possible to cause a different file to be accessed other than that intended. This issue was exploited by adding a null byte (%00) which resulted in the application ignoring the rest of the supplied value after the null byte.
The Vulnerability Laboratory Research Team discovered a file include & arbitrary file upload vulnerability in the Flux Player 3.1.0 (Apple iOS - iPad & iPhone). A file include web vulnerability is detected in the Flux Player 3.1.0 Application (Apple iOS - iPad & iPhone). The file include vulnerability allows remote attackers to include (upload) local file or path requests to compromise the application or service. A remote file upload web vulnerability is detected in the Flux Player 3.1.0 Application (Apple iOS - iPad & iPhone). The file upload vulnerability allows remote attackers to upload and execute malicious files on the application side.
A local file include and arbitrary file upload web vulnerability is detected in the WiFly 1.0 Pro application (Apple iOS - iPad & iPhone). The vulnerabilities are located in the file upload module of the web-server (http://localhost:4885/) when processing to request to upload a file. The vulnerability allows an attacker (remote) to upload files with malicious code to compromise the application or connected device.
Open Windows movie maker in left panel click on 'Import audio or music' and choose movieMaker.wav
Php script 'admin/fckeditor_dialog_image.php' line 101 and 'extensions/saurus4/captcha_image.php' line 28 have insufficient sanitization of user-supplied data which leads to Local File Inclusion vulnerability.
The vulnerability allows an remote attacker to inject own malicious script codes on the application-side of the vulnerable module. The vulnerability is located in the `kbox_login_form` value of the `kbox_login_form` parameter. Remote attackers are able to inject own malicious script codes to the vulnerable `kbox_login_form` value. The request method to inject is POST and the attack vector is located on the application-side. The injection point is the `kbox_login_form` value of the `kbox_login_form` parameter. The execution of the injected script code occurs in the main login page of the vulnerable module.
Light Audio Mixer Version 1.0.12 is vulnerable to a crash due to a buffer overflow. After creating a PoC file (.wav), dragging it to the Play List and choosing a Deck (if present) and pressing OK will cause the application to crash.
The vulnerability allows remote attackers to inject malicious script codes on the application-side of the vulnerable service. The vulnerability is located in the `name` and `description` value of the `upload` module. Remote attackers are able to inject own malicious script codes to the application-side of the vulnerable service. The request method to inject is POST and the attack vector is located on the application-side. The security risk of the persistent input validation web vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 5.6.