This module exploits a memory corruption flaw in Microsoft XML Core Services when trying to access an uninitialized Node with the getDefinition API, which may corrupt memory allowing remote code execution.
Huawei HG866 GPON routers don't properly validate the session on every page. It is possible to change the web interface admin password by performing an unauthenticated post directly to the form.
Karafun will crash and not responding when trying to close it after runs a special crafted .m3u file.
A boundary error in the Xfpx.dll module when processing FlashPix images can be exploited to cause a heap-based buffer overflow via a specially crafted FPX file.
A boundary error in the NCSEcw.dll module when decompressing Enhanced Compressed Wavelet images can be exploited to cause a heap-based buffer overflow via a specially crafted ECW file.
An integer truncation error when processing Sun Raster images can be exploited to cause a heap-based buffer overflow via a specially crafted 'Depth' value in a RAS file.
Multiple vulnerabilities has been discovered in News Script PHP v1.2 CMS. The vulnerabilities are located in the `index.php` and `admin.php` files. Input validation vulnerabilities allow remote attackers to inject malicious script codes to the application-side of the vulnerable module. The request method to inject is POST and the attack vector is located on the application-side.
An attacker can exploit a Local File Inclusion vulnerability in php-decoda 3.3.1 to read arbitrary files on the server. This is due to a lack of proper validation of the 'view' parameter in the 'index.php' script, which allows an attacker to include arbitrary files on the web server.
This module exploits the ComSndFTP FTP Server version 1.3.7 beta by sending a specially crafted format string specifier as a username. The crafted username is sent to to the server to overwrite the hardcoded function pointer from Ws2_32.dll!WSACleanup. Once this function pointer is triggered, the code bypasses dep and then repairs the pointer to execute arbitrary code. The SEH exit function is preferred so that the administrators are not left with an unhandled exception message. When using the meterpreter payload, the process will never die, allowing for continuous exploitation.
This module exploits a buffer overflow in MMPlayer 2.2 The vulnerability is triggered when opening a malformed M3U/PPL file that contains an overly long string, which results in overwriting a SEH record, thus allowing arbitrary code execution under the context of the user.