header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WordPress Plugin Advanced Custom Fields Remote File Inclusion

This module exploits a remote file inclusion flaw in the WordPress blogging software plugin known as Advanced Custom Fields. The vulnerability allows for remote file inclusion and remote code execution via the export.php script. The Advanced Custom Fields plug-in versions 3.5.1 and below are vulnerable. This exploit only works when the php option allow_url_include is set to On (Default Off).

Astium VoIP PBX <= v2.1 build 25399 Multiple Vulns Remote Root Exploit

Astium is prone to multiple vulnerabilities. This exploit will use SQL injection to bypass authentication on the login page and get access as an administrator. After that it will upload and execute a PHP script which will modify the "/usr/local/astium/web/php/config.php" script with our reverse shell php code and run a "sudo /sbin/service astcfgd reload" (Apache user is allowed to restart this service through sudo). The service reload will cause the added code in "/usr/local/astium/web/php/config.php" to be executed as root and thus resulting in a reverse shell with root privileges. Code in "/usr/local/astium/web/php/config.php" is also removed again, else the web interface will stop functioning!

e107 v1.0.1 Administrator CSRF Resulting in Arbitrary Javascript Execution

A Cross-Site Request Forgery vulnerability exists in the /e107_admin/newspost.php?create function, in which an attacker can create a malicious POST request that could be sent by a logged in e107 Administrator (upon visiting a malicious site using an iFrame known as a drive-by attack, or other means). This is possible since e-tokens or any other request validation is not used during this type of request. The severity of this vulnerability increases when the Administrator has the ability to post News Items containing javascript. This results in an attacker having the ability to force an administrator to post any arbitrary javascript to the front page of the e107 site. Also, once posted, the resulting page: /e107/e107_admin/newspost.php displays the new content to the Administrator, and if this javascript is set in the news_title POST parameter, it is executed on this page in the context of the Administrator. This results in the ability for an attacker to use any type of javascript attack at this point in time on the Administrator through the backend news items, and/or on the front end to any logged in user that may visit this page. What naturally comes to mind is session hijacking through established User/Administrator cookies.

Joomla Component (com_spidercalendar) Blind SQL Injection Vulnerability

A Blind SQL Injection vulnerability was discovered in the Joomla component com_spidercalendar. The vulnerability is caused due to the lack of input validation in the 'date' parameter of the 'index.php' script when handling a 'GET' request. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

aktiv-player version 2.80

A buffer overflow vulnerability exists in aktiv-player version 2.80, which allows an attacker to execute arbitrary code by creating a specially crafted WMA file. The vulnerability is due to insufficient boundary checks when processing WMA files. An attacker can exploit this vulnerability by creating a malicious WMA file and sending it to the target user. When the target user opens the malicious file, the attacker can execute arbitrary code on the target system.

Grep <2.11 is vulnerable to int overflow exploitation

Grep <2.11 is vulnerable to int overflow exploitation. Although it is patched in the recent Grep, this update has not been pushed to the Ubuntu repos, or the Redhat repos, leaving 99% of those OS's(and more) vulnerable. There are also many other ways to do this bug. It is low severity because it would be extremely hard to actually exploit it, and it is a local exploit, and it is not run by root.

Microsoft Internet Explorer CDwnBindInfo Object Use-After-Free Vulnerability

This module exploits a vulnerability found in Microsoft Internet Explorer. A use-after-free condition occurs when a CDwnBindInfo object is freed by FollowHyperlink2, but a reference is kept in CDoc. As a result, when the reference is used again during a page reload, an invalid memory that's controllable is used, and allows arbitrary code execution under the context of the user.

Recent Exploits: