This module exploits a vulnerability found in HP System Management Homepage. By supplying a specially crafted HTTP request, it is possible to control the 'tempfilename' variable in function JustGetSNMPQueue (found in ginkgosnmp.inc), which will be used in a exec() function. This results in arbitrary code execution under the context of SYSTEM. Please note: In order for the exploit to work, the victim must enable the 'tftp' command, which is the case by default for systems such as Windows XP, 2003, etc.
This module exploits a vulnerability found in ZPanel's htpasswd module. When creating .htaccess using the htpasswd module, the username field can be used to inject system commands, which is passed on to a system() function for executing the system's htpasswd's command.
This application has an upload feature that allows an authenticated user with Administrator roles or User roles to upload arbitrary files cause remote code execution by simply request it.
The vulnerability is caused by missing input validation in the ping_ip parameter and can be exploited to inject and execute arbitrary shell commands. You need to be authenticated to the device or you have to find other methods for inserting the malicious commands.
PEiD is an intuitive application that relies on its user-friendly interface to detect packers, cryptors and compilers found in PE executable files. A crafted EXE can be used as POC to trigger the Crash of PEiD version 0.95.
This exploit allows an attacker to gain root access on a Seowonintech device. The exploit is triggered by sending a GET request to the device's /cgi-bin/diagnostic.cgi page, which will then allow the attacker to send a GET request to the /cgi-bin/system_config.cgi page, granting them root access.
Collabtive 1.0 is vulnerable to a SQL injection vulnerability. An authenticated user can exploit this vulnerability to drop a web shell on the server. The web shell can be used to execute arbitrary commands on the server.
The buffer overflow vulnerability resides in the Add subject functionality, and it's triggered when the user will submit a large string when specifying the school subject name. To trigger the vulnerability go to the main menu, select subjects, click new then generate a string with the code below and the software will execute the shellcode which will popup a MessageBox.
Multiple Blind SQL Injection vulnerabilities were detected in the Alienvault OSSIM Open Source SIEM 4.1 product. An example POC was provided, which included a GET parameter injection in the sensor, tcp_flags, and tcp_port fields.
An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The request should contain a malicious SQL query in the 'gid' parameter. This will allow the attacker to execute arbitrary SQL commands on the underlying database.