The Vulnerability Laboratory Research Team discovered multiple vulnerabilities in the FTP Sprite 1.2.1 application (Apple iOS). The vulnerability allows remote attackers to inject malicious persistent script codes on application-side (persistent) of the vulnerable service. The vulnerability is located in the `name` and `url` value of the `add` module. Remote attackers are able to inject own malicious script codes to application-side. The request method to inject is POST and the attack vector is located on the application-side.
rpcbind can be crashed by setting the argument length value > 8944 in an RPC CALLIT procedure request over UDP.
This PoC exploits a denial of service vulnerability in Squid 3.3.5. The vulnerability is triggered when a specially crafted HTTP request is sent to the Squid service. The request contains a large Host header with 2000 'yc' characters. This causes the Squid service to crash and respawn.
Multiple vulnerabilities, such as Cross-Site Scripting (XSS) and SQL injection were identified in the latest version of McAfee ePO (4.6.6). All identified vulnerabilities were discovered post authentication. The SQL injection vulnerability was identified in the GET and POST requests, while the Reflected XSS vulnerability was identified in the POST requests.
Multiple vulnerabilities, including Cross-Site Scripting(XSS) and SQL injection were identified in the latest version of BMC SERVICE DESK EXPRESS. SQL injection vulnerabilities were identified in the /SDE/DashBoardGUI.aspx page with vulnerable parameters ASPSESSIONIDASSRATTQ, TABLE_WIDGET_1, TABLE_WIDGET_2, browserDateTimeInfo, browserNumberInfo, and UID. Reflected XSS vulnerabilities were identified in the /SDE/QV_admin.aspx, /SDE/QV_grid.aspx, and /SDE/commonhelp.aspx pages with vulnerable parameters SelTab, CallBack, and HelpPage respectively.
This module exploits a stack-based buffer overflow vulnerability in version 1.11 of Corel PDF Fusion. The vulnerability exists while handling a XPS file with long entry names. In order for the payload to be executed, an attacker must convince the target user to open a specially crafted XPS file with Corel PDF Fusion. By doing so, the attacker can execute arbitrary code as the target user.
WordPress Plugin Spicy Blogroll is vulnerable to a file inclusion vulnerability. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'link_url' and 'link_text' parameters of the 'spicy-blogroll-ajax.php' script. An attacker can exploit this vulnerability to include arbitrary files from local resources. Successful exploitation requires that 'allow_url_include' is set to 'On' in the 'php.ini' configuration file.
The vulnerability exists due to a flaw in the PLC's ability to handle a Modbus packet with the bit quantity of coils set to 0. When sending this malformed packet the device crashes and fails to recover without manual intervention. Once an engineer manually reboots the device it will recover from the crash.
This exploit is a proof-of-concept for a remote code execution vulnerability in nginx versions 1.3.9 and 1.4.0. It is unlikely to succeed when used against remote internet hosts due to the non-blocking read() used by nginx. The exploit does not break stack cookies but makes use of a reliable method to retrieve all needed offsets for Linux x86 and pop a shell.
When UPnP services and WAN http administrative access are enabled, authorization and credential challenges can be bypassed by directly accessing root privileged abilities via a web browser URL. All aspects of the modem/router can be changed, altered and controlled by an attacker, including gaining access to and changing the PPPoe/PPP ISP credentials.