wddx_serialize_value and wddx_serialize_vars functions fails to handle Variant object when it is given as a first argument. Also functions stream_bucket_prepend and stream_bucket_append have some problems with handling Variant object when given as a second argument.
A persistent XSS vulnerability exists in Vanilla Version 2.0.18.4 + Latest Comment 1.1 plugin. An attacker can create a new thread with an XSS payload as the thread title, which will appear on the index page of the forum.
This module exploits a buffer overflow in Foxit Reader 3.0 builds 1301 and earlier. Due to the way Foxit Reader handles the input from an 'Launch' action, it is possible to cause a stack-based buffer overflow, allowing an attacker to gain arbitrary code execution under the context of the user.
DVD-Lab Studio File Denial of service vulnerability, when opening a malicious .PCX file, the exploit can be triggered by going to file->Open
Real-DRAW PRO 5.2.4 crashes while importing a crafted PNG, WMF, PSD, TGA, TTF, BMP, TIFF and PCX file. To trigger the exploit, go to file->Import.
This module exploits a vulnerability found in HP's StorageWorks P4000 VSA, versions prior to 9.5. By using a default account credential, it is possible to inject arbitrary commands as part of a ping request via port 13838.
PHP Address Book 7.0.0 is prone to multiple XSS and SQLi vulnerabilities. XSS PoC-Exploits include: http://[target]/addressbookv7.0.0/preferences.php?from='"</script><script>alert('xss')</script>, http://[target]/addressbookv7.0.0/group.php/" /><script> alert('xss')</script>, http://[target]/addressbookv7.0.0/index.php?group='"</script><script>alert(document.cookie)</script>. SQLi PoC-Exploits include: http://[target]/addressbookv7.0.0/edit.php?id=1 AND 1=IF(1<2,2,1), http://[target]/addressbookv7.0.0/edit.php?id=1 AND 1=IF(1>2,2,1), http://[target]/addressbookv7.0.0/view.php?id=1' UNION ALL SELECT NULL, NULL, version(), NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL--+
This module exploits an arbitrary code injection vulnerability in the chat module that is part of Active Collab by abusing a preg_replace() using the /e modifier and its replacement string using double quotes. The vulnerable function can be found in activecollab/application/modules/chat/functions/html_to_text.php.
This module exploits a stack based buffer overflow in the BEA Weblogic Apache plugin. The connector fails to properly handle specially crafted HTTP POST requests, resulting a buffer overflow due to the insecure usage of sprintf. Currently, this module works over Windows systems without DEP, and has been tested with Windows 2000 / XP.
This module abuses the SVG support to execute Java Code in the Squiggle Browser included in the Batik framework 1.7 through a crafted svg file referencing a jar file. In order to gain arbitrary code execution, the browser must meet the following conditions: (1) It must support at least SVG version 1.1 or newer, (2) It must support Java code and (3) The 'Enforce secure scripting' check must be disabled.