header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

NetIQ Privileged User Manager 2.3.1 ldapagnt_eval() Remote Perl Code Execution

This module abuses a lack of authorization in the NetIQ Privileged User Manager service (unifid.exe) to execute arbitrary perl code. The problem exists in the ldapagnt module. The module has been tested successfully on NetIQ PUM 2.3.1 over Windows 2003 SP2, which allows to execute arbitrary code with SYSTEM privileges.

simple lighttpd 1.4.31 DOS POC

This exploit is a proof of concept for a denial of service vulnerability in lighttpd version 1.4.31. The vulnerability is triggered by sending a specially crafted HTTP request with a 'TE' header that is not followed by a valid value. This causes the server to enter an infinite loop, resulting in a denial of service.

Stored XSS in PHP Server Monitor

PHP Server Monitor is vulnerable to stored XSS. On the 'Add server' page, when inserting HTML code into the Label name or IP field, it can cause the whole page to be corrupted. An attacker can use this vulnerability to execute malicious JavaScript code, such as alerting the user's cookie information.

ManageEngine ServiceDesk 8.0 – Multiple Vulnerabilities

Multiple persistent input validation vulnerabilities are detected in ManageEngines ServiceDesk v8.0 Plus web application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Two vulnerabilities are located in the my details and request new incidents module of the web front-end with the bound vulnerable name, subject and description parameters. Exploitation requires low user inter action & low privileged customer web application user account. The secound part of the bugs are located in the New Contract, Access points and Create Solution module of the admin/moderator back-end with the bound vulnerable title, asset name, contract name, description or support name. Successful exploitation of the vulnerability can lead to session hijacking (customer/manage) or stable (persistent) context manipulation. Exploitation of the persistent vulnerabilities results in account steal, persistent phishing attacks, persistent external redirects and persistent manipulation of affected or connected module context.

Adobe Reader 10.1.4 JP2KLib&CoolType WriteAV Vulnerability

The parsing routine is really complicated. Write AV by some kind of not properly initialized array. But the parameters of memmove, the counter and destiny pointer seems controllable with data from flatedecoded data. The wierd thing is the stream encoded with flatedecode can't decode properly via zlib.decompress, but Adobe seems decode it correctly.

Narcissus Image Configuration Passthru Vulnerability

This module exploits a vulnerability found in Narcissus image configuration function. This is due to the backend.php file not handling the $release parameter properly, and then passes it on to the configure_image() function. In this function, the $release parameter can be used to inject system commands for passthru (a PHP function that's meant to be used to run a bash script by the vulnerable application), which allows remote code execution under the context of the web server.

LAN.FS Messenger v2.4 – Command Execution Vulnerability

A command execution vulnerability is detected in the official LAN.FS v2.4 Messenger Software. The vuln allows remote attackers to execute system specific commands with system privileges. The vulnerability is located in the `message` value of the `send` POST method request. Remote attackers are able to inject own malicious commands to compromise the system.

WordPress Facebook Survey v1 – SQL Injection Vulnerability

A blind SQL Injection vulnerability is detected in the commercial Wordpress Facebook Survey Pro Plugin. The vulnerability allows an attacker (remote) or local low privileged user account to execute a SQL commands on the affected application dbms. The blind sql injection vulnerability is located in index.php file (timeline module) with the bound vulnerable id parameter. Successful exploitation of the vulnerability results in dbms & application compromise. Exploitation requires no user interaction & without privileged application user account.

Recent Exploits: