header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

PHP <= 5.4.3 wddx_serialize_* / stream_bucket_* Variant Object Null Ptr Derefernce

wddx_serialize_value and wddx_serialize_vars functions fails to handle Variant object when it is given as a first argument. Also functions stream_bucket_prepend and stream_bucket_append have some problems with handling Variant object when given as a second argument.

Vanilla LatestComment 1.1 Plugin Persistant XSS Vulnerability

A persistent XSS vulnerability exists in Vanilla Version 2.0.18.4 + Latest Comment 1.1 plugin. An attacker can create a new thread with an XSS payload as the thread title, which will appear on the index page of the forum.

Foxit Reader 3.0 Open Execute Action Stack Based Buffer Overflow

This module exploits a buffer overflow in Foxit Reader 3.0 builds 1301 and earlier. Due to the way Foxit Reader handles the input from an 'Launch' action, it is possible to cause a stack-based buffer overflow, allowing an attacker to gain arbitrary code execution under the context of the user.

PHP Address Book 7.0.0 Multiple security vulnerabilities

PHP Address Book 7.0.0 is prone to multiple XSS and SQLi vulnerabilities. XSS PoC-Exploits include: http://[target]/addressbookv7.0.0/preferences.php?from='"</script><script>alert('xss')</script>, http://[target]/addressbookv7.0.0/group.php/" /><script> alert('xss')</script>, http://[target]/addressbookv7.0.0/index.php?group='"</script><script>alert(document.cookie)</script>. SQLi PoC-Exploits include: http://[target]/addressbookv7.0.0/edit.php?id=1 AND 1=IF(1<2,2,1), http://[target]/addressbookv7.0.0/edit.php?id=1 AND 1=IF(1>2,2,1), http://[target]/addressbookv7.0.0/view.php?id=1' UNION ALL SELECT NULL, NULL, version(), NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL--+

Active Collab “chat module” <= 2.3.8 Remote PHP Code Injection Exploit

This module exploits an arbitrary code injection vulnerability in the chat module that is part of Active Collab by abusing a preg_replace() using the /e modifier and its replacement string using double quotes. The vulnerable function can be found in activecollab/application/modules/chat/functions/html_to_text.php.

Oracle Weblogic Apache Connector POST Request Buffer Overflow

This module exploits a stack based buffer overflow in the BEA Weblogic Apache plugin. The connector fails to properly handle specially crafted HTTP POST requests, resulting a buffer overflow due to the insecure usage of sprintf. Currently, this module works over Windows systems without DEP, and has been tested with Windows 2000 / XP.

Squiggle 1.7 SVG Browser Java Code Execution

This module abuses the SVG support to execute Java Code in the Squiggle Browser included in the Batik framework 1.7 through a crafted svg file referencing a jar file. In order to gain arbitrary code execution, the browser must meet the following conditions: (1) It must support at least SVG version 1.1 or newer, (2) It must support Java code and (3) The 'Enforce secure scripting' check must be disabled.

Recent Exploits: