header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

SAP NetWeaver Dispatcher DiagTraceR3Info Buffer Overflow

This module exploits a stack buffer overflow in the SAP NetWeaver Dispatcher service. The overflow occurs in the DiagTraceR3Info() function and allows a remote attacker to execute arbitrary code by supplying a special crafted Diag packet. The Dispatcher service is only vulnerable if the Developer Traces have been configured at levels 2 or 3. The module has been successfully tested on SAP Netweaver 7.0 EHP2 SP6 over Windows XP SP3 and Windows 2003 SP2 (DEP bypass).

Security Advisory AA-004: Directory Traversal Vulnerability in Sitecom Home Storage Center

An attacker can read arbitrary files, including the files that stores the administrative password. This means an attacker could steal sensitive data stored on the device, leverage the device to drop and/or host malware, abuse the device to send spam through the victim’s Internet connection, and use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.

Security Advisory AA-003: Directory Traversal Vulnerability in Conceptronic Grab’n’Go Network Storage

An attacker can read arbitrary files, including the files that stores the administrative password. This means an attacer could steal sensitive data stored on the device; leverage the device to drop and/or host malware; abuse the device to send spam through the victim’s Internet connection; use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.

AV Arcade Free Edition Blind SQL Injection

AV Arcade Free Edition is vulnerable to Blind SQL Injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameter 'id' in the 'add_rating.php' page. This can allow the attacker to gain access to the database and potentially execute arbitrary code.

Joomla spider calendar lite Remote Exploit

Spider Calendar Lite is a highly configurable Joomla extension which allows you to have multiple organized events in a calendar. An attacker can exploit a SQL injection vulnerability in the com_spidercalendar component to gain access to the Joomla database and extract sensitive information such as usernames and passwords.

Adobe Photoshop CS6 PNG Parsing Heap Overflow

Adobe Photoshop is a graphics editing program developed and published by Adobe Systems Incorporated. Adobe's 2003 'Creative Suite' rebranding led to Adobe Photoshop 8's renaming to Adobe Photoshop CS. Thus, Adobe Photoshop CS6 is the 13th major release of Adobe Photoshop. The CS rebranding also resulted in Adobe offering numerous software packages containing multiple Adobe programs for a reduced price. Adobe Photoshop is released in two editions: Adobe Photoshop, and Adobe Photoshop Extended, with the Extended having extra 3D image creation, motion graphics editing, and advanced image analysis features. Alongside Photoshop and Photoshop Extended, Adobe also publishes Photoshop Elements and Photoshop Lightroom, collectively called 'The Adobe Photoshop Family'. In 2008, Adobe released Adobe Photoshop Express, a free web-based image editing tool to edit photos directly on blogs and social networking sites; in 2011 a version was released for the Android operating system and the iOS operating system.

OTRS Open Technology Real Services Cross-Site Scripting Vulnerability

OTRS Open Technology Real Services versions 3.1.8 and 3.1.9 are vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can exploit this vulnerability by sending a malicious HTML email containing a specially crafted payload to a victim. The payload is then executed in the victim's browser, allowing the attacker to gain access to the victim's session and potentially execute arbitrary code.

War FTP Daemon Remote Format String Vulnerability

War FTP Daemon is vulnerable to a remote format string vulnerability. An attacker can send a maliciously crafted username and password to the FTP server, which can cause the server to crash. This can be exploited by sending a username and password containing format string specifiers to the FTP server.

vBulletin Yet Another Awards System 4.0.2 Time Based SQL Injection 0day

The vulnerability exists within /request_award.php. The $award_request_uid is used within an insert into statement, unsanitized. The POC is http://[site].com/request_award.php with POST: do=submit&name=award_id=[VALID REWARD ID]&award_request_reason=0&award_request_uid=0[SQL]&submit=Submit

Internet Download Manager All Versions – Memory Corruption Vulnerability

A vulnerability in Internet Download Manager (IDM) allows attackers to execute arbitrary code by importing a specially crafted IDM export file. The vulnerability exists due to a boundary error when processing the file, which can be exploited to cause a stack-based buffer overflow. Successful exploitation of this vulnerability may allow attackers to execute arbitrary code in the context of the application.

Recent Exploits: