Upload document (personal or Shared) functionallity of application allow unrestricted file upload. This can be abused by the attacker to upload backdoor to webserver. The persistent cross site scripting vulnerability exists in 'add news information section'. A remote attacker with privileges can exploit this vulnerablity.
A vulnerability in LibreOffice 3.5.3 allows an attacker to cause a crash when a particular .rtf file is opened. This was tested on Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 build 7601. The vulnerability is caused due to a boundary error when processing .rtf files and can be exploited to cause a stack-based buffer overflow via a specially crafted .rtf file.
PBBoard 2.1.4 is vulnerable to Local File Inclusion. An attacker can exploit this vulnerability to include local files on the server. This vulnerability exists due to insufficient sanitization of user-supplied input to the 'page' parameter in 'admin.php' script. An attacker can include local files on the server by supplying a relative pathname in the 'page' parameter. This can be exploited to execute arbitrary PHP code on the vulnerable server.
Due to improper input sanitization, pretty much every conceivable parameter is SQL injectable. Although to exploit many of these parameters, one needs to be logged in, but the main page (index.php) offers a form to send a recipient a message. This form does not require authentication.
This module exploits a vulnerability found in WeBid version 1.0.2. By abusing the converter.php file, a malicious user can inject PHP code in the includes/currencies.php script without any authentication, which results in arbitrary code execution.
This module exploits a vulnerability found in QuickShare File Share's FTP service. By supplying '../' in the file path, it is possible to trigger a directory traversal flaw, allowing the attacker to read a file outside the virtual directory. By default, the 'Writable' option is enabled during account creation, therefore this makes it possible to create a file at an arbitrary location, which leads to remote code execution.
This exploit requires no authentication and uses a payload to create a script in the /tmp/networkScript directory which is sudoable and apache writable. The payload is encoded in base64 and is then executed using a PHP shell_exec command. The trigger is a GET request to the releasenotes.php file with a relative path to the access_log file.
A vulnerability has been discovered in Apple Safari Browser included in the last version of iOS (5.1.1). When JavaScript function match() gets a big buffer as parameter the browser unexpectedly crashes. By extension, the function search() is affected too.
This module exploits a vulnerability found in RabidHamster R4's web server. By supplying a malformed HTTP request, it is possible to trigger a stack-based buffer overflow when generating a log, which may result in arbitrary code execution under the context of the user.
Social Engine versions 4.2.2 is vulnerable to XSS and CSRF. For XSS, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. For CSRF, the product does not, or can be induced to not, use an appropriate mechanism to verify the source of a request prior to performing an action.