This module exploits a stack buffer overflow in the SAP NetWeaver Dispatcher service. The overflow occurs in the DiagTraceR3Info() function and allows a remote attacker to execute arbitrary code by supplying a special crafted Diag packet. The Dispatcher service is only vulnerable if the Developer Traces have been configured at levels 2 or 3. The module has been successfully tested on SAP Netweaver 7.0 EHP2 SP6 over Windows XP SP3 and Windows 2003 SP2 (DEP bypass).
An attacker can read arbitrary files, including the files that stores the administrative password. This means an attacker could steal sensitive data stored on the device, leverage the device to drop and/or host malware, abuse the device to send spam through the victim’s Internet connection, and use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.
An attacker can read arbitrary files, including the files that stores the administrative password. This means an attacer could steal sensitive data stored on the device; leverage the device to drop and/or host malware; abuse the device to send spam through the victim’s Internet connection; use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.
AV Arcade Free Edition is vulnerable to Blind SQL Injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameter 'id' in the 'add_rating.php' page. This can allow the attacker to gain access to the database and potentially execute arbitrary code.
Spider Calendar Lite is a highly configurable Joomla extension which allows you to have multiple organized events in a calendar. An attacker can exploit a SQL injection vulnerability in the com_spidercalendar component to gain access to the Joomla database and extract sensitive information such as usernames and passwords.
Adobe Photoshop is a graphics editing program developed and published by Adobe Systems Incorporated. Adobe's 2003 'Creative Suite' rebranding led to Adobe Photoshop 8's renaming to Adobe Photoshop CS. Thus, Adobe Photoshop CS6 is the 13th major release of Adobe Photoshop. The CS rebranding also resulted in Adobe offering numerous software packages containing multiple Adobe programs for a reduced price. Adobe Photoshop is released in two editions: Adobe Photoshop, and Adobe Photoshop Extended, with the Extended having extra 3D image creation, motion graphics editing, and advanced image analysis features. Alongside Photoshop and Photoshop Extended, Adobe also publishes Photoshop Elements and Photoshop Lightroom, collectively called 'The Adobe Photoshop Family'. In 2008, Adobe released Adobe Photoshop Express, a free web-based image editing tool to edit photos directly on blogs and social networking sites; in 2011 a version was released for the Android operating system and the iOS operating system.
OTRS Open Technology Real Services versions 3.1.8 and 3.1.9 are vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can exploit this vulnerability by sending a malicious HTML email containing a specially crafted payload to a victim. The payload is then executed in the victim's browser, allowing the attacker to gain access to the victim's session and potentially execute arbitrary code.
War FTP Daemon is vulnerable to a remote format string vulnerability. An attacker can send a maliciously crafted username and password to the FTP server, which can cause the server to crash. This can be exploited by sending a username and password containing format string specifiers to the FTP server.
The vulnerability exists within /request_award.php. The $award_request_uid is used within an insert into statement, unsanitized. The POC is http://[site].com/request_award.php with POST: do=submit&name=award_id=[VALID REWARD ID]&award_request_reason=0&award_request_uid=0[SQL]&submit=Submit
A vulnerability in Internet Download Manager (IDM) allows attackers to execute arbitrary code by importing a specially crafted IDM export file. The vulnerability exists due to a boundary error when processing the file, which can be exploited to cause a stack-based buffer overflow. Successful exploitation of this vulnerability may allow attackers to execute arbitrary code in the context of the application.