header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Dell PacketTrap PSA 7.1 – Multiple Persistent Vulnerabilities

Multiple persistent input validatino web vulnerabilities are detected in the DELL packetTrap PSA v7.1 web-application. The vulnerability allows remote attackers to inject own malicious script codes to the application-side of the vulnerable module. The persistent vulnerabilities are located in the `/psa/` directory of the web-application. Remote attackers are able to inject malicious script codes to the vulnerable `name` and `description` parameters of the `/psa/add_edit_service.php` module. The execution of the malicious script code occurs in the `/psa/service_list.php` module.

Dell PacketTrap MSP RMM 6.6.x – Multiple Persistent Web Vulnerabilities

Multiple persistent input validaiton web vulnerabilities are detected in the DELL PacketTrap 6.6.23938 MSP RMM Software. The vulnerability allows remote attackers to implement/inject malicious script code on the application-side (persistent). The vulnerabilities are located in the `name` and `description` value of the `add/edit` module. Remote attackers are able to inject own malicious persistent script codes to the vulnerable `name` and `description` values. The request method to inject is POST and the attack vector is located on the application-side.

Xibo Directory Traversal Vulnerability

Directory traversal vulnerabilities occur when user input is used in the construction of a filename or directory path which is subsequently used in some system function. If the input is not correctly validated or directory permissions not correctly set, it may be possible to cause a different file to be accessed other than that intended. This issue was exploited by adding a null byte (%00) which resulted in the application ignoring the rest of the supplied value after the null byte.

Flux Player v3.1.0 iOS – File Include & Arbitrary File Upload Vulnerability

The Vulnerability Laboratory Research Team discovered a file include & arbitrary file upload vulnerability in the Flux Player 3.1.0 (Apple iOS - iPad & iPhone). A file include web vulnerability is detected in the Flux Player 3.1.0 Application (Apple iOS - iPad & iPhone). The file include vulnerability allows remote attackers to include (upload) local file or path requests to compromise the application or service. A remote file upload web vulnerability is detected in the Flux Player 3.1.0 Application (Apple iOS - iPad & iPhone). The file upload vulnerability allows remote attackers to upload and execute malicious files on the application side.

WiFly 1.0 Pro iOS – Multiple Web Vulnerabilities

A local file include and arbitrary file upload web vulnerability is detected in the WiFly 1.0 Pro application (Apple iOS - iPad & iPhone). The vulnerabilities are located in the file upload module of the web-server (http://localhost:4885/) when processing to request to upload a file. The vulnerability allows an attacker (remote) to upload files with malicious code to compromise the application or connected device.

Dell Kace 1000 SMA v5.4.70402 – Persistent Vulnerabilities

The vulnerability allows an remote attacker to inject own malicious script codes on the application-side of the vulnerable module. The vulnerability is located in the `kbox_login_form` value of the `kbox_login_form` parameter. Remote attackers are able to inject own malicious script codes to the vulnerable `kbox_login_form` value. The request method to inject is POST and the attack vector is located on the application-side. The injection point is the `kbox_login_form` value of the `kbox_login_form` parameter. The execution of the injected script code occurs in the main login page of the vulnerable module.

Olive File Manager v1.0.1 iOS – Multiple Vulnerabilities

The vulnerability allows remote attackers to inject malicious script codes on the application-side of the vulnerable service. The vulnerability is located in the `name` and `description` value of the `upload` module. Remote attackers are able to inject own malicious script codes to the application-side of the vulnerable service. The request method to inject is POST and the attack vector is located on the application-side. The security risk of the persistent input validation web vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 5.6.

Recent Exploits: