header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WebPageTest Arbitrary PHP File Upload

This module exploits a vulnerability found in WebPageTest's Upload Feature. By default, the resultimage.php file does not verify the user-supplied item before saving it to disk, and then places this item in the web directory accessable by remote users. This flaw can be abused to gain remote code execution.

ME Mobile Application Manager v10 – SQL Vulnerabilities

The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms without user inter action.

Joomla com_movm SQL Injection

Movm is a joomla extension for mobiles which optimize VirtueMart sites for iphone, android and blackberry. It is compatible with Joomla2.5 and VirtueMart 2.0. This component can be Attacked from a mobile, put the following string in the url field: p0C http://server/index.php?option=com_movm&controller=product&task=product&id=999999'+UNION+ALL+SELECT+1%2C2%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2Cdatabase()+FROM+information_schema.schemata--+D4NB4R%20

pBot Remote Code Execution (“*” hostauth)

pBot is a PHP IRC bot that is vulnerable to remote code execution due to the use of an insecure hostauth value. An attacker can send a malicious payload to the bot, which will then be executed on the server. This payload can be used to delete the bot's originating script, and cause the bot to die.

eGlibc Signedness Vulnerability

On the 24th of February 2010 a patch was provided to the main Glibc tree which added optimisation support for 64 bit processors by adding unsigned conditional jumps to support > 2GB data sizes. If an attacker could control the length parameter supplied memcpy, it may be possible to cause the application to execute user controllable code. This has been verified and tested on a fully patched and up to date installation of Ubuntu 10.4 LTS against various applications. When this is the case, an attacker controllable length value is used to calculate the jump table pointer index in the optimized copy function. Setting the length value to a negative number will cause a jmp instruction to be skipped due to an signedness vulnerbility, resulting in attacker supplied value being used to calculate the location of a jump table function, resulting in malicious code execution.

Joomla com_niceajaxpoll <= 1.3.0 SQL Injection Vulnerability

There is a SQL Injection vulnerability that can be called from within the website to perform the SQL Injection attack. The impact of this vulnerability should be rated as critical as it is possible to access the database and therefore retrieve user information such as usernames, passwords and other data. When abused, hackers could gain access to the administrative interface of Joomla.

Dr. Web Control Center Admin UI Remote Script Code Injection

Dr. Web Enterprise Security Suite is managed via a web based interface called Control Center. If an attacker suplies java script code instead of a username on the login page, this script code will be automatically executed every time an administrative user is viewing the audit log. This attack can be used to steal authentication cookies or to drive further attacks.

Blind SQLi POC

This exploit is a proof of concept for a Blind SQL Injection vulnerability. It attempts to dump out the first available hash in the users table of spywall_db. It does this by sending a series of requests to the server, each of which contains a different value for a single character in the hash. If the request takes longer than the specified time, the value is assumed to be correct. The exploit then moves on to the next character in the hash.

Microsoft Office SharePoint Server 2007 Remote Code Execution

This module exploits a vulnerability found in SharePoint Server 2007 SP2. The software contains a directory traversal, that allows a remote attacker to write arbitrary files to the filesystem, sending a specially crafted SOAP ConvertFile request to the Office Document Conversions Launcher Service, which results in code execution under the context of 'SYSTEM'. The module uses uses the Windows Management Instrumentation service to execute an arbitrary payload on vulnerable installations of SharePoint on Windows 2003 Servers.

Recent Exploits: