Cyclope Employee Surveillance Solution v6.0 is vulnerable to Local File Include, SQL Injection and Change Admin account's password. Local File Include vulnerability can be exploited by sending a crafted HTTP request containing a maliciously crafted URL to the vulnerable server. SQL Injection vulnerability can be exploited by sending a crafted HTTP request containing maliciously crafted data to the vulnerable server. Change Admin account's password vulnerability can be exploited by sending a crafted HTTP request containing maliciously crafted data to the vulnerable server.
xt:Commerce, commerce:SEO and Gambio versions <= v3.04 SP2.1, v2.1 CE and v2.0.10 SP1.4 are vulnerable to a time based blind SQL injection vulnerability. The vulnerability exists due to insufficient sanitization of the $pagename variable in the xtc_check_permission() function in the admin/includes/functions/general.php file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands in the context of the vulnerable application.
MaxForum v1.0.0 is vulnerable to Local File Inclusion. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'max_lang' cookie parameter in the '/MaxForum/includes/forums/warn_popup.php' script. A remote attacker can exploit this vulnerability to include arbitrary files from local resources and execute arbitrary PHP code on the vulnerable system.
The MobileCartly 1.0 application is vulnerable to remote file upload. An attacker can upload a malicious file to the /images/uploadprocess.php and /includes/logo-upload-process.php scripts, which can then be accessed from the /productimages/ and /images/logo/ directories respectively.
This module exploits a path traversal flaw in Novell ZENworks Asset Management 7.5. By exploiting the CatchFileServlet, an attacker can upload a malicious file outside of the MalibuUploadDirectory and then make a secondary request that allows for arbitrary code execution.
This module exploits a SQL injection found in Cyclope Employee Surveillance Solution. Because the login script does not properly handle the user-supplied username parameter, a malicious user can manipulate the SQL query, and allows arbitrary code execution under the context of 'SYSTEM'.
This module exploits a vulnerability in TestLink version 1.9.3 or prior. This application has an upload feature that allows any authenticated user to upload arbitrary files to the '/upload_area/nodes_hierarchy/' directory with a randomized file name. The file name can be retrieved from the database using SQL injection.
Viscatory is a local privilege escalation vulnerability in Viscosity, an OS X VPN client. The SUID helper will execute site.py in its enclosing folder, allowing a simple symlink to gain root access.
This PoC exploits a null pointer dereference vulnerability in Pure-FTPd. It has been tested with Pure-FTPd v1.0.21 on CentOS 6.2 and Ubuntu 8.04. The latest version (v1.0.36) is not affected. The PoC sends a specially crafted PASV command to the FTP server, which causes a segmentation fault and crashes the server.
Malicious user is able to access other user's files and filespaces. The attack can be executed by sending a GET request to the URL /transfer/?start=0&count=10&metadata=fteSamplesUser=user1. The malicious user should know the file name and the related ID before executing the attack. The malicious user can access the URL /filespace/user1/414d512057514d542020202020202020eb3bfc4f2030df02/changedthisfilename.txt using a GET request.