header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

HP System Management Homepage JustGetSNMPQueue Command Injection

This module exploits a vulnerability found in HP System Management Homepage. By supplying a specially crafted HTTP request, it is possible to control the 'tempfilename' variable in function JustGetSNMPQueue (found in ginkgosnmp.inc), which will be used in a exec() function. This results in arbitrary code execution under the context of SYSTEM. Please note: In order for the exploit to work, the victim must enable the 'tftp' command, which is the case by default for systems such as Windows XP, 2003, etc.

ZPanel 10.0.0.2 htpasswd Module Username Command Execution

This module exploits a vulnerability found in ZPanel's htpasswd module. When creating .htaccess using the htpasswd module, the username field can be used to inject system commands, which is passed on to a system() function for executing the system's htpasswd's command.

Seowonintech all device remote root exploit v2

This exploit allows an attacker to gain root access on a Seowonintech device. The exploit is triggered by sending a GET request to the device's /cgi-bin/diagnostic.cgi page, which will then allow the attacker to send a GET request to the /cgi-bin/system_config.cgi page, granting them root access.

ASC Timetables 2013 – Stack Buffer Overflow Vulnerability

The buffer overflow vulnerability resides in the Add subject functionality, and it's triggered when the user will submit a large string when specifying the school subject name. To trigger the vulnerability go to the main menu, select subjects, click new then generate a string with the code below and the software will execute the shellcode which will popup a MessageBox.

TopGamesScript-v1.2 (play.php) Sql Injection Vulnerability

An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The request should contain a malicious SQL query in the 'gid' parameter. This will allow the attacker to execute arbitrary SQL commands on the underlying database.

Recent Exploits: