Due to improperly sanitized user input a SQL Injection is present in the 'Forgot Password' page of ClipBucket 2.5 (and maybe older versions). The payload used in the PoC is -1' or sleep(5) and '1'='1.
A vulnerability in Symantec Web Gateway <= 5.0.3.18 allows an attacker to change the password of any user on the system. This is due to the lack of authentication when sending a POST request to the temppassword.php page. An attacker can send a POST request with the new password and the username of the target user, and the password will be changed without any authentication.
Multiple vulnerabilities have been found in SAP Netweaver that could allow an unauthenticated, remote attacker to execute arbitrary code and lead to denial of service conditions. The vulnerabilities are triggered sending specially crafted SAP Diag packets to remote TCP port 32NN (being NN the SAP system number) of a host running the 'Dispatcher' service, part of SAP Netweaver Application Server ABAP. By sending different messages, the different vulnerabilities can be triggered.
It is possible to access the file upload page '?upload_to=' without the need to authenticate (log in) to the XODA system. An attacker is able to upload a web shell to the server and gain unauzhorized access to the operating system. For the stored XSS, an attacker can enter a malicious payload in the file description or filters field and when the page is reloaded, the XSS will be triggered.
This module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.64. This issue was fixed in 5.66. In order to trigger the vulnerability valid credentials with the create folder permission must be provided. The HTTP option must be enabled on Sysax too. This module will log into the server, get a SID token, find the root folder, and then proceed to exploit the server. Successful exploits result in SYSTEM access. This exploit works on XP SP3, and Server 2003 SP1-SP2.
IOServer is a piece of industrial control software that runs on Windows. It contains a built-in web server to support the "XML Server" feature. This web server can be abused to download any file on the file system without authentication, if the "Root Directory" setting does not contain a trailing backslash. Note that a sample configuration provided with the product exhibits a vulnerable configuration.
Uebimiau is an universal webmail developed in PHP by Aldoir Ventura. It is vulnerable to Stored XSS in e-mail body, 'Title' field and Address Book. XSS payloads can be used to exploit these vulnerabilities.
YourArcadeScript 2.4 is vulnerable to an SQL injection vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data or modify the application's data.
Hivemail Webmail is vulnerable to multiple stored XSS issues. An attacker can send an email to the victim with the payload in the message body, email body (HREF), contacts or calendar. XSS will be triggered when victim opens the message, clicks on the link, view his contacts or view his calendar.
A CSRF vulnerability exists in PG Portal Pro, which allows an attacker to change the password of an administrator account. This is done by sending a malicious POST request to the admin_settings.php page, which contains the new password and confirmation of the new password. The attacker can then use the new password to gain access to the administrator account.