This exploit is a local kernel DoS vulnerability in Microsoft Windows XP SP3. It uses the NtUserCreateWindowEx() function to create a window with a malicious parameter, which causes the system to crash.
The denial of service, happens on mikrotik router's winbox service when the attacker is requesting continuesly a part of a .dll/plugin file, so the service becomes unstable causing every remote clients (with winbox) to disconnect and denies to accept any further connections. Sending requests specially crafted for the winbox service, can cause a 100% denial of winbox sevice.
STRATO Newsletter Manager is vulnerable to a directory traversal attack. An attacker can use the Google Dork 'inurl:"newsletter.php.cgi"' to find vulnerable websites. The exploit is a URL with the following structure: http://server/cgi-bin/newsletter.php.cgi?PHPSESSID=af92ed633ae0d06d1e24d22520f709f7&action=nl_show&nl=../../../../../../../../../../../../../../etc/passwd. This URL can be used to access sensitive files on the server, such as the /etc/passwd file.
Multiple remote SQL Injection and Cross Site Scripting vulnerabilities are detected in the MyClientBase Content Management System v0.12. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise. The vulnerability is located on invoice & tag when processing to request the invoices & tags list. The vulnerability also allows an attacker (remote) or local low privileged user account to inject own malicious script codes on the application side (persistent). Successful exploitation of the vulnerability results in session hijacking, client-side phishing attacks, malicious redirects and non-persistent manipulation of affected or connected module context.
OpenCart is a turn-key ready 'out of the box' shopping cart solution. A vulnerability exists in OpenCart version 1.5.2.1, where user submitted GET parameter 'route' is used as argument for class Action initialization. This can lead to remote file disclosure and remote code execution.
This modules exploits a vulnerability found in McAfee Virtual Technician's MVTControl. This ActiveX control can be abused by using the GetObject() function to load additional unsafe classes such as WScript.Shell, therefore allowing remote code execution under the context of the user.
A SQL Injection vulnerability is detected in GENU CMS 2012.3. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise.
A SQL Injection vulnerability is detected in DIY v1.0 Content Management System. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Multiple non persistent cross site scripting vulnerability is detected in DIY v1.0 Content Management System. The vulnerability allows remote attackers to hijack website customer, moderator or admin sessions with high required user interaction or local low privileged user account. A cross site request forgery vulnerability is detected in DIY v1.0 Content Management System. The vulnerability allows remote attackers to perform unauthorized actions on the vulnerable application.
A remote SQL Injection vulnerability is detectedin Opial v2 Content Management System. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. A persistent input valiation web vulnerability is detected in the Opial v2 Content Management System. The vulnerability allows remote attackers to inject own malicious script codes to the application-side of the vulnerable module.
The persistent Cross-Site Scripting vulnerability is located in the `name` value of the `contact` module. Remote attackers are able to inject own malicious script codes to the vulnerable application module. The execution of the malicious script code occurs in the `search` module of the `contact` module. The request method to inject is POST and the attack vector is located on the application-side of the service.