header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

MPlayer SAMI Subtitle File Buffer Overflow

This module exploits a stack-based buffer overflow found in the handling of SAMI subtitles files in MPlayer SVN Versions before 33471. It currently targets SMPlayer 0.6.8, which is distributed with a vulnerable version of mplayer. The overflow is triggered when an unsuspecting victim opens a movie file first, followed by loading the malicious SAMI subtitles file from the GUI. Or, it can also be done from the console with the mplayer "-sub" option.

Ganesha Digital Library 4.0 Multiple Vulnerabilities

Ganesha Digital Library (GDL) is a digital library software developed by Knowledge Management Research Group (KMRG) Institute of Technology Bandung (ITB) in order to harness the intellectual capital (intellectual capital) of ITB, which includes academic articles, journals, the final task, thesis, dissertation, research results, expertise and other directory. There is a security flaw (NON-Persistent XSS) in the Account Activation Section. Activate Account in the left corner Menu. Then you'll be taken to Activate Account Page, Fill this script : '"><script>alert(1337)</script> on the Account Field and Code Field Then Click Activate. XSS Script : '"><script>alert(1337)</script> For Example : http://server/pustaka/searc h.php?q='"><script>alert(1337)</script> http://server/pustaka/office.php?m=1'

Microsoft Wordpad 5.1 (.doc) Null Pointer Dereference Vulnerability

This vulnerability is caused by a null pointer dereference in Microsoft Wordpad 5.1 (.doc). It is not related to CWE 2009-0259. The proof of concept involves a binary diff of a template file (proper empty doc document) and a malformed file, which shows the offset that differs. Access violation occurs when reading [00000004]. The registers are eax = 020ebb72, ebx = 00000000, ecx = 020ebb7c, edx = 00090608, esi = 00000000, edi = 01bc04a8, eip = 01b9dbbb, esp = 0177f5c8, ebp = 0177f5cc. The function dump is 01b9dbb4 55, 01b9dbb5 8bec, 01b9dbb7 56, 01b9dbb8 8b7508, 01b9dbbb 807e0400, 01b9dbbf 751b, 01b9dbc1 8b06, 01b9dbc3 57, 01b9dbc4 8b78fc, 01b9dbc7 57, 01b9dbc8 ff156010b801, 01b9dbce 57, 01b9dbcf ff157410b801, 01b9dbd5 56, 01b9dbd6 e87bfdffff, 01b9dbdb 5f, 01b9dbdc 5e, 01b9dbdd 5d. Proof of concept is available at http://cond.psychodela.pl/d/ms-wordpad-nullptr.rar and https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18952.rar.

NewsAdd <=1.0 Multiple SQL Injection

The first vulnerability is in the search form, on index. Paste this in it: %' UNION ALL SELECT 1,group_concat(concat(email,0x3c3d3e,usuario,0x3c3d3e,senha,0x3c3d3e,admin,0x3c3d3e,banido)),3,4,5 from usuarios-- wc. You will get a unique line like: admin@admin.com.br<=>admin<=>e10adc3949ba59abbe56e057f20f883e<=>1<=>0,user@email.com<=>user<=>ee11cbb19052e40b07aac0ca060c23ee<=>1<=>0. Lines are separated by commas (",") and columns, by "<=>". In the return, we have two lines: admin@admin.com.br<=>admin<=>e10adc3949ba59abbe56e057f20f883e<=>1<=>0 user@email.com<=>user<=>ee11cbb19052e40b07aac0ca060c23ee<=>1<=>0. Here, we have the email, username, password (md5) and admin status.

PBBoard v2.1.4 multiple SQLi Vulnerabilities

Due to improper sanitization, many of the parameters are injectable. Need a user account to trigger these. By changing the 'id' number used in the 'where' clause, an attacker can modify another user's settings. Additionally, an XSS attack can be performed using the MySQL's error message.

ispVM System XCF File Handling Overflow

This module exploits a vulnerability found in ispVM System 18.0.2. Due to the way ispVM handles .xcf files, it is possible to cause a buffer overflow with a specially crafted file, when a long value is supplied for the version attribute of the ispXCF tag. It results in arbitrary code execution under the context of the user.

WinRadius Server Denial Of Service Vulnerability

WinRadius is a standard RADIUS server for network authentication, accounting. It's easy to use, and can be used for telecommunication accounting platform, PPP authentication, accounting server. It support PPP, PPPoE, PPTP, VPN, VoIP, ADSL, Cable Modem, CDMA, GSM, GPRS, WLAN(802.1x), etc. WinRadius server would bind udp port 1812 and 1813, but it does not validate the password option size leading to a Denial Of Service flaw while sending more than 240 characters to it.

PHP Volunteer Management System v 1.0.2 multiple SQLi Vulnerabilities

Due to improper sanitation, many of the parameters are injectable, some need to be authenticated, others not. An example of a payload is /?p=dashboard' and sleep(5) and '1'='1. Other affected parameters can be found in the message section of the application when reading or deleting a message. An example of a payload is /?p=read_message&id=-1' or '1'='1.

Recent Exploits: