MediaCoder PMP Edition 0.8.17 is vulnerable to a buffer overflow vulnerability due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by supplying a specially crafted M3U file, which when opened in MediaCoder PMP Edition 0.8.17, can cause a buffer overflow and allow arbitrary code execution.
A SEH buffer overflow vulnerability exists in All Mediacoder Product when a specially crafted m3u file is opened. This could allow an attacker to execute arbitrary code in the context of the application.
This exploit is used to gain root privileges on FreeBSD 9.0 and 9.1 systems. It uses the mmap and ptrace system calls to copy the contents of the exploit binary into the timedc binary, which is then executed with root privileges.
Input passed via the POST parameter 'users_id_assign' in '/ajax/ticketassigninformation.php' script, POST parameter 'filename' in '/front/document.form.php' script, and POST parameter 'table' in 'glpi/ajax/comments.php' script is not properly sanitised before being used in SQL queries. This can be exploited by a malicious attacker to manipulate SQL queries by injecting arbitrary SQL code in the affected application.
This exploit is for MusicBee v2.0.4663. It creates a malicious .m3u file with a header of 'http://' and a buffer of 5000 'A' characters. When the file is opened, it causes a denial of service.
TP-Link TL PS110U Print Server runs telnet service which enables an attacker to access the configuration details without authentication. The PoC can extract device name, MAC address, manufacture name, Printer model, and SNMP Community Strings.
Restricted access to this script isn't properly realized (Don't require authentication) , so an attacker might be able to upload arbitrary files containing malicious PHP code due to uploaded file extension isn't properly checked.
A vulnerability has been identified in Simple File Manager v.024, which could be exploited by attackers to bypass security restrictions into admin panel. An attacker can exploit this issue using a browser. The attacker can bypass the authentication process by setting the username and password parameters to a null value.
The SPBAS Business Automation Software is vulnerable to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). An attacker can inject malicious code into the first name and last name fields of the ‘My Info’ page, as well as the security question field. Additionally, an attacker can craft a malicious HTML page to change customer information and security question answer.
An attacker might write to arbitrary files or inject arbitrary code into a file with this vulnerability. User tainted data is used when creating the file name that will be opened or when creating the string that will be written to the file. An attcker can exploit this vulnerability to upload a malicious file to the server and execute arbitrary code.