This module abuses a lack of authorization in the NetIQ Privileged User Manager service (unifid.exe) to execute arbitrary perl code. The problem exists in the ldapagnt module. The module has been tested successfully on NetIQ PUM 2.3.1 over Windows 2003 SP2, which allows to execute arbitrary code with SYSTEM privileges.
This exploit is a proof of concept for a denial of service vulnerability in lighttpd version 1.4.31. The vulnerability is triggered by sending a specially crafted HTTP request with a 'TE' header that is not followed by a valid value. This causes the server to enter an infinite loop, resulting in a denial of service.
PHP Server Monitor is vulnerable to stored XSS. On the 'Add server' page, when inserting HTML code into the Label name or IP field, it can cause the whole page to be corrupted. An attacker can use this vulnerability to execute malicious JavaScript code, such as alerting the user's cookie information.
Multiple persistent input validation vulnerabilities are detected in ManageEngines ServiceDesk v8.0 Plus web application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Two vulnerabilities are located in the my details and request new incidents module of the web front-end with the bound vulnerable name, subject and description parameters. Exploitation requires low user inter action & low privileged customer web application user account. The secound part of the bugs are located in the New Contract, Access points and Create Solution module of the admin/moderator back-end with the bound vulnerable title, asset name, contract name, description or support name. Successful exploitation of the vulnerability can lead to session hijacking (customer/manage) or stable (persistent) context manipulation. Exploitation of the persistent vulnerabilities results in account steal, persistent phishing attacks, persistent external redirects and persistent manipulation of affected or connected module context.
The parsing routine is really complicated. Write AV by some kind of not properly initialized array. But the parameters of memmove, the counter and destiny pointer seems controllable with data from flatedecoded data. The wierd thing is the stream encoded with flatedecode can't decode properly via zlib.decompress, but Adobe seems decode it correctly.
SQL Injection via search form. You can query to get some info about administrator account and something...
This module exploits a vulnerability found in Narcissus image configuration function. This is due to the backend.php file not handling the $release parameter properly, and then passes it on to the configure_image() function. In this function, the $release parameter can be used to inject system commands for passthru (a PHP function that's meant to be used to run a bash script by the vulnerable application), which allows remote code execution under the context of the web server.
A command execution vulnerability is detected in the official LAN.FS v2.4 Messenger Software. The vuln allows remote attackers to execute system specific commands with system privileges. The vulnerability is located in the `message` value of the `send` POST method request. Remote attackers are able to inject own malicious commands to compromise the system.
A blind SQL Injection vulnerability is detected in the commercial Wordpress Facebook Survey Pro Plugin. The vulnerability allows an attacker (remote) or local low privileged user account to execute a SQL commands on the affected application dbms. The blind sql injection vulnerability is located in index.php file (timeline module) with the bound vulnerable id parameter. Successful exploitation of the vulnerability results in dbms & application compromise. Exploitation requires no user interaction & without privileged application user account.
FormatFactory v3.0.1 is vulnerable to a buffer overflow vulnerability when handling specially crafted profile files. This can be exploited to execute arbitrary code by tricking a user into opening a malicious profile file.