header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WordPress Plugins – MM Forms Community Arbitrary File Upload Vulnerability

A vulnerability in the MM Forms Community plugin for Wordpress allows an attacker to upload arbitrary files, such as a web shell, via a crafted HTTP request. This vulnerability affects versions 2.2.5 and 2.2.6 of the plugin. An attacker can exploit this vulnerability by sending a crafted HTTP request containing a malicious file to the doajaxfileupload.php script. The malicious file will be uploaded to the upload/temp/ directory, allowing an attacker to execute arbitrary code on the server.

WordPress Plugins – WordPress Font Uploader Shell Upload Vulnerability

A vulnerability in the WordPress Font Uploader plugin allows an attacker to upload a malicious PHP file to the server. The vulnerability is due to the lack of file type validation in the plugin. An attacker can exploit this vulnerability by uploading a malicious PHP file with a .ttf extension. This will allow the attacker to execute arbitrary code on the server.

WordPress Plugins – Asset Manager Shell Upload Vulnerability

A vulnerability in the Asset Manager plugin for Wordpress allows an attacker to upload a malicious PHP file to the server. This can be done by sending a POST request to the upload.php file with the malicious file as a parameter. The malicious file can then be accessed at the URL http://www.exemple.com/wordpress/wp-content/uploads/assets/temp/lo.php

WordPress Plugins – HTML5 AV Manager for WordPress Shell Upload Vulnerability

A vulnerability in the HTML5 AV Manager for WordPress plugin (version 0.2.7) allows an attacker to upload a malicious PHP file via a POST request to the custom.php script. This can be exploited to execute arbitrary PHP code on the vulnerable system.

WordPress Plugins – WP Marketplace Shell Upload Vulnerability

A vulnerability in the WP Marketplace plugin for Wordpress allows an attacker to upload a malicious PHP file to the server. This can be done by sending a POST request to the uploadify.php file with the malicious file in the Filedata parameter. The malicious file can then be accessed at the uploadify directory on the server.

WordPress Plugins – WP-Property – WordPress Powered Real Estate and Property Management Shell Upload Vulnerability

A vulnerability in the WP-Property plugin for WordPress allows an attacker to upload a malicious PHP shell to the server. This is achieved by sending a specially crafted POST request to the uploadify.php script, which is vulnerable to a directory traversal attack. The malicious PHP shell can then be accessed via a URL.

Sielco Sistemi Winlog Buffer Overflow <= v2.07.16

Winlog Lite is the entry level version of the SCADA/HMI software Winlog Pro offered by Sielco Sistemi to allow an evaluation of the potentiality and the simplicity of use of the package; Winlog Lite is also a powerful and low cost solution for creation of small supervisory applications. The vulnerability can be triggered by sending a specially crafted request to port 46824.

PyroCMS 2.1.1 CRLF Injection And Stored XSS Vulnerability

PyroCMS suffers from a stored XSS and HTTP Response Splitting vulnerability when parsing user input to the 'title' and 'redirect_to' parameters via POST method thru 'index.php' script. Attackers can exploit these weaknesses to execute arbitrary HTML and script code in a user's browser session or insert arbitrary HTTP headers, which are included in a response sent to the user.

Apache Struts <= 2.2.1.1 Remote Command Execution

This module exploits a remote command execution vulnerability in Apache Struts versions < 2.2.1.1. This issue is caused because the ExceptionDelegator interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

Recent Exploits: