Hexamail Server suffers persistent XSS vulnerability in the mail body, allowing malicious user to execute scripts in a victim’s browser to hijack user sessions, redirect users, and or hijack the user’s browser. By sending a malicious script to the victim email, the webmail automatically load the mail body, so the script will be automatically executed without permission from user.
Sysax <= 5.60 is vulnerable to a buffer overflow vulnerability when a maliciously crafted Country Name field is entered into the Create Certificate page. This can lead to code execution on the vulnerable system.
Vanilla Version 2.0.18.4 is vulnerable to stored XSS. An attacker can create a new thread and post their XSS as a tag. The attacker can bypass the max-length on the form by using a proxy or manipulating the form. Once the thread is posted, an administrator or moderator can be sent to the URL http://server/index.php?p=/vanilla/post/editdiscussion/7, where 7 is the thread ID of the thread just made. The XSS will then trigger. The URL may be different depending on what category the thread is in.
To create the XSS firstly create a new thread. Once the thread is made press attach the poll and either enter the XSS in the title or the answers of the poll. The XSS I used is <script>alert('xss')</script>
This exploit causes a denial of service in PHP 5.3.10 by using the spl_autoload_call() function with a buffer of 9999 'A's. This exploit has been tested on Windows 7 64bit, English, Apache, PHP 5.3.10.
This exploit causes a denial of service in PHP 5.3.10 by using the spl_autoload_register() function with a large string as an argument. This causes the application to crash.
This exploit causes a denial of service in PHP 5.3.10 by using the spl_autoload() function with a string of 9999 'A's. This causes the application to crash.
This module exploits the 'Ajax File and Image Manager' component that can be found in log1 CMS. In function.base.php of this component, the 'data' parameter in writeInfo() allows any malicious user to have direct control of writing data to file data.php, which results in arbitrary remote code execution.
This plugin is based on the default tagging plugin that comes with Vanilla. Therefore this is vulnerable to the same attack. Create a new thread and post your XSS as tag. Once you have posted the thread, send an administrator or moderator to http://target.tld/index.php?p=/vanilla/post/editdiscussion/7, where 7 is the thread ID of the thread you just made. The XSS will then trigger.
This module exploits a buffer overflow in the script-fu server component on GIMP <= 2.6.12. By sending a specially crafted packet, an attacker may be able to achieve remote code execution under the context of the user.