header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

PhpTax pfilez Parameter Exec Remote Code Injection

This module exploits a vulnerability found in PhpTax, an income tax report generator. When generating a PDF, the icondrawpng() function in drawimage.php does not properly handle the pfilez parameter, which will be used in a exec() statement, and then results in arbitrary remote code execution under the context of the web server. Please note: authentication is not required to exploit this vulnerability.

gom player 2.1.44.5123 (Unicode) NULL pointer dereference

A NULL pointer dereference vulnerability exists in GOM Player 2.1.44.5123 (Unicode). An attacker can exploit this vulnerability by crafting a malicious AVI file and sending it to the victim. When the victim opens the malicious file, the application will crash due to the NULL pointer dereference.

FL Studio 10 Producer Edition – SEH Based Buffer Overflow PoC

Fl Studio is Prone to a SEH based Buffer Overflow which allows attacker to execute arbitary code on the victim's machine. To trigger the vulnerability the attacker must fake the 'Browser Extra search folder' path & paste the input released from this PoC. Looking a little bit deeper in the stack & in the EBP register we will see that the software will try to create a file named e.g. BBBBCCCC.NFO. Then the EIP is overwritten with the SEH address. The Exploit will look like this : [Junk 'A' x 416] [6 Bytes Jump + 2Nops ] [p/p/r address or other] [Shellcode].

Endpoint Protector v4.0.4.0 – Multiple Web Vulnerabilities

Multiple persistent input validation vulnerabilities are detected in Endpoint Protector v4.0.4.0 Appliance Application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Successful exploitation of the vulnerability can lead to session hijacking (manager/admin) or stable (persistent) context manipulation. Exploitation requires low user interaction.

FastStone Image Viewer 4.6 <= ReadAVonIP Arbitrary Code Execution

A vulnerability in FastStone Image Viewer 4.6 allows an attacker to execute arbitrary code by crafting a malicious GIF file. This vulnerability is due to a stack-based buffer overflow in the ReadAVonIP() function of the FSViewer.exe application. By sending a specially crafted GIF file, an attacker can cause a stack-based buffer overflow, which can be exploited to execute arbitrary code.

Hardcoreview WriteAV Arbitrary Code Execution

A vulnerability in Hardcoreview WriteAV allows an attacker to execute arbitrary code. This vulnerability is caused by a buffer overflow in the WriteAV function, which is triggered when a crafted .gif file is opened. This can lead to a denial of service or the execution of arbitrary code with the privileges of the user running the application.

Novell Sentinel Log Manager ver. <=1.2.0.2 allows unauthenticated users configuring retention policies

Novell Sentinel Log Manager version 1.2.0.2 and earlier allows unauthenticated users to configure retention policies. An attacker can send a crafted HTTP request to the server to exploit this vulnerability.

Recent Exploits: