header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Cyclope Employee Surveillance Solution v6.0

Cyclope Employee Surveillance Solution v6.0 is vulnerable to Local File Include, SQL Injection and Change Admin account's password. Local File Include vulnerability can be exploited by sending a crafted HTTP request containing a maliciously crafted URL to the vulnerable server. SQL Injection vulnerability can be exploited by sending a crafted HTTP request containing maliciously crafted data to the vulnerable server. Change Admin account's password vulnerability can be exploited by sending a crafted HTTP request containing maliciously crafted data to the vulnerable server.

xt:Commerce <= v3.04 SP2.1, commerce:SEO <= v2.1 CE, Gambio <= v2.0.10 SP1.4 Time Based Blind SQL Injection

xt:Commerce, commerce:SEO and Gambio versions <= v3.04 SP2.1, v2.1 CE and v2.0.10 SP1.4 are vulnerable to a time based blind SQL injection vulnerability. The vulnerability exists due to insufficient sanitization of the $pagename variable in the xtc_check_permission() function in the admin/includes/functions/general.php file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands in the context of the vulnerable application.

MaxForum v1.0.0 Local File Inclusion

MaxForum v1.0.0 is vulnerable to Local File Inclusion. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'max_lang' cookie parameter in the '/MaxForum/includes/forums/warn_popup.php' script. A remote attacker can exploit this vulnerability to include arbitrary files from local resources and execute arbitrary PHP code on the vulnerable system.

MobileCartly 1.0 Remote File Upload Vulnerability

The MobileCartly 1.0 application is vulnerable to remote file upload. An attacker can upload a malicious file to the /images/uploadprocess.php and /includes/logo-upload-process.php scripts, which can then be accessed from the /productimages/ and /images/logo/ directories respectively.

Novell ZENworks Asset Management Remote Execution

This module exploits a path traversal flaw in Novell ZENworks Asset Management 7.5. By exploiting the CatchFileServlet, an attacker can upload a malicious file outside of the MalibuUploadDirectory and then make a secondary request that allows for arbitrary code execution.

Cyclope Employee Surveillance Solution v6 SQL Injection

This module exploits a SQL injection found in Cyclope Employee Surveillance Solution. Because the login script does not properly handle the user-supplied username parameter, a malicious user can manipulate the SQL query, and allows arbitrary code execution under the context of 'SYSTEM'.

TestLink v1.9.3 Arbitrary File Upload Vulnerability

This module exploits a vulnerability in TestLink version 1.9.3 or prior. This application has an upload feature that allows any authenticated user to upload arbitrary files to the '/upload_area/nodes_hierarchy/' directory with a randomized file name. The file name can be retrieved from the database using SQL injection.

Pure-FTPd Crash PoC (Null Pointer Dereference)

This PoC exploits a null pointer dereference vulnerability in Pure-FTPd. It has been tested with Pure-FTPd v1.0.21 on CentOS 6.2 and Ubuntu 8.04. The latest version (v1.0.36) is not affected. The PoC sends a specially crafted PASV command to the FTP server, which causes a segmentation fault and crashes the server.

Privilege Escalation in WebSphereMQ File Transfer Edition

Malicious user is able to access other user's files and filespaces. The attack can be executed by sending a GET request to the URL /transfer/?start=0&count=10&metadata=fteSamplesUser=user1. The malicious user should know the file name and the related ID before executing the attack. The malicious user can access the URL /filespace/user1/414d512057514d542020202020202020eb3bfc4f2030df02/changedthisfilename.txt using a GET request.

Recent Exploits: