header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

OpenOffice OLE Importer DocumentSummaryInformation Stream Handling Overflow

This module exploits a vulnerability in OpenOffice 2.3.1 and 2.3.0 on Microsoft Windows XP SP3. By supplying a OLE file with a malformed DocumentSummaryInformation stream, an attacker can gain control of the execution flow, which results arbitrary code execution under the context of the user.

appRain CMF Arbitrary PHP File Upload Vulnerability

This module exploits a vulnerability found in appRain's Content Management Framework (CMF), version 0.1.5 or less. By abusing the uploadify.php file, a malicious user can upload a file to the uploads/ directory without any authentication, which results in arbitrary code execution.

Symantec End Point Protection 11.x & Symantec Network Access Control 11.x Local Code Execution POC

A vulnerability exists in Symantec End Point Protection 11.x & Symantec Network Access Control 11.x due to improper validation of user-supplied input. An attacker can exploit this vulnerability by crafting a malicious XML file and sending it to the vulnerable system. This can allow the attacker to execute arbitrary code on the vulnerable system.

FlexNet License Server Manager lmgrd Buffer Overflow

This module exploits a vulnerability in the FlexNet License Server Manager. The vulnerability is due to the insecure usage of memcpy in the lmgrd service when handling network packets, which results in a stack buffer overflow. In order to improve reliability, this module will make lots of connections to lmgrd during each attempt to maximize its success.

Novell Client 4.91 SP3/4 Privilege escalation exploit

A vulnerability exists in Novell Client 4.91 SP3/4 which allows an attacker to gain elevated privileges. The vulnerability is due to a buffer overflow in the Novell Client which can be exploited by an attacker to execute arbitrary code with elevated privileges. The vulnerability is due to insufficient bounds checking of user-supplied input when handling certain requests. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable application. Successful exploitation of this vulnerability can result in the attacker gaining elevated privileges.

PHP <= 5.4.3 (com_event_sink) Code Execution Proof of Concept

This is a very strange bug and I had a really hard time trying to classify it, but lets start from the beginning. As we can read in PHP manual : com_event_sink function connects events from COM object to a PHP object. First argument should be a COM object. But when I set it up to new Variant(), PHP instance crashed. After few minutes of research it was clear to me that we can control EAX register by defining first parameter of our Variant object. The proof of concept code located below should produce situation similar to this : eax=024e0050 ebx=010328f0 ecx=41414141 edx=00c0facc esi=0121ff68 edi=00000000 eip=100f33d5 esp=00c0faa8 ebp=00000000 iopl=0 nv up ei pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200202 IMHO it is possible to write a reliable exploit using i.e.: ROP method but due to lack of free time and skill I leave this task to someone else. Also 0in tried to write stable exploit for same bug in com_print_typeinfo() function but as far as I know it isn't stable enough :(

Recent Exploits: