header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

eFile Wifi Transfer Manager 1.0 iOS – Multiple Vulnerabilities

The Vulnerability Laboratory Research Team discovered multiple vulnerabilities in the eFile Wifi Manager v1.0 iOS mobile application. A local file include and an arbitrary file upload web vulnerability via POST request method is detected in the eFile Wifi Manager v1.0 iOS mobile application for the apple ipad & iphone. The vulnerability allows remote attackers vi http request to upload and execute arbitrary files on the application-side of the vulnerable device. Additionally, a local file include web vulnerability is detected in the eFile Wifi Manager v1.0 iOS mobile application. The vulnerability allows remote attackers to include local files to compromise the application or device.

PCMan’s FTP Server 2.0 Remote Buffer Overflow Exploit

PCMan's FTP Server 2.0 is vulnerable to a remote buffer overflow exploit. The exploit is triggered when a malicious user sends a specially crafted MKD command with an overly long payload. This causes a buffer overflow, which can be used to execute arbitrary code on the vulnerable system.

PHP-Charts v1.0 Remote Code Execution Exploit

This exploit allows an attacker to execute arbitrary code on a vulnerable system. It takes advantage of a vulnerability in the PHP-Charts v1.0 application, which allows an attacker to inject malicious code into the 'wizard/index.php' file. The malicious code is then executed when the file is accessed.

Novell Client 2 SP3 nicm.sys Local Privilege Escalation

This module exploits a flaw in the nicm.sys driver to execute arbitrary code in kernel space. The vulnerability occurs while handling ioctl requests with code 0x143B6B, where a user provided pointer is used as function pointer. The module has been tested successfully on Windows 7 SP1 with Novell Client 2 SP3.

ZPanel zsudo Local Privilege Escalation Exploit

This module abuses the zsudo binary, installed with zpanel, to escalate privileges. In order to work, a session with access to zsudo on the sudoers configuration is needed. This module is useful for post exploitation of ZPanel vulnerabilities, where typically web server privileges are acquired, and this user is allowed to execute zsudo on the sudoers file.

Advanced Medal System SQL Injection

This vulnerability allows an attacker to inject arbitrary SQL commands into the 'advmedsys_view.php' script. The vulnerable code is located in lines 17-23 and 232 of the script. An attacker can exploit this vulnerability by crafting a malicious URL and sending it to a victim. The URL should contain the malicious SQL code in the 'e_QUERY' parameter. For example, http://site.com/plugins/advmedsys_view.php?profile.*SQL HERE*

MoinMoin twikidraw Action Traversal File Upload

This module exploits a vulnerability in MoinMoin 1.9.5. The vulnerability exists on the manage of the twikidraw actions, where a traversal path can be used in order to upload arbitrary files. Exploitation is achieved on Apached/mod_wsgi configurations by overwriting moin.wsgi, which allows to execute arbitrary python code, as exploited in the wild on July, 2012.

LibrettoCMS File Manager Arbitary File Upload Vulnerability

This module exploits a file upload vulnerability found in LibrettoCMS 1.1.7, and possibly prior. Attackers bypass the file extension check and abuse the upload feature in order to upload a malicious PHP file without authentication, which results in arbitary remote code execution.

Recent Exploits: