header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

MS12-043 Microsoft XML Core Services MSXML Uninitialized Memory Corruption

This module exploits a memory corruption flaw in Microsoft XML Core Services when trying to access an uninitialized Node with the getDefinition API, which may corrupt memory allowing remote code execution.

News Script PHP v1.2 – Multiple Web Vulnerabilites

Multiple vulnerabilities has been discovered in News Script PHP v1.2 CMS. The vulnerabilities are located in the `index.php` and `admin.php` files. Input validation vulnerabilities allow remote attackers to inject malicious script codes to the application-side of the vulnerable module. The request method to inject is POST and the attack vector is located on the application-side.

ComSndFTP v1.3.7 Beta USER Buffer Overflow

This module exploits the ComSndFTP FTP Server version 1.3.7 beta by sending a specially crafted format string specifier as a username. The crafted username is sent to to the server to overwrite the hardcoded function pointer from Ws2_32.dll!WSACleanup. Once this function pointer is triggered, the code bypasses dep and then repairs the pointer to execute arbitrary code. The SEH exit function is preferred so that the administrators are not left with an unhandled exception message. When using the meterpreter payload, the process will never die, allowing for continuous exploitation.

Recent Exploits: