A SQL injection vulnerability exists in the Joomla component com_estateagent. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This can allow the attacker to execute arbitrary SQL commands on the underlying database.
Mini-stream RM-MP3 Converter� V 3.1.2.2 is vulnerable to a local buffer overflow vulnerability. An attacker can exploit this vulnerability by crafting a malicious .m3u file with a specially crafted header and a payload of 17416 bytes of A characters followed by a return address of 7C874413. This will cause the program to execute the payload, which is a shellcode that will open a command prompt.
Dolibarr is prone to remote command execution vulnerability because the software fails to adequately sanitize user-supplied input. A command injection attack can be executed if specially crafted parameters are sent. Successful attacks can compromise the affected Web Server and its software.
This module exploits a vulnerability found in Dolibarr ERP/CRM's backup feature. This software is used to manage a company's business information such as contacts, invoices, orders, stocks, agenda, etc. When processing a database backup request, the export.php function does not check the input given to the sql_compat parameter, which allows a remote authenticated attacker to inject system commands into it, and then gain arbitrary code execution.
This module allows remote attackers to execute arbitrary code by exploiting the Snort service via crafted SMB traffic. The vulnerability is due to a boundary error within the DCE/RPC preprocessor when reassembling SMB Write AndX requests, which may result a stack-based buffer overflow with a specially crafted packet sent on a network that is monitored by Snort. Vulnerable versions include Snort 2.6.1, 2.7 Beta 1 and SourceFire IDS 4.1, 4.5 and 4.6.
A CSRF vulnerability exists in Utopia News Pro 1.4.0 which allows an attacker to add an admin user to the application. An attacker can craft a malicious HTML page containing a form with hidden fields that when submitted, will add an admin user to the application. The form action is set to the vulnerable URL and the form fields contain the parameters required to add an admin user.
This exploit creates a malicious M3U file with 500000 'H' characters, which when opened with Play [EX] 2.1 causes a denial of service.
Multiple Buffer Overflow vulnerabilities are detected on AnvSoft Any Video Converter Free / Pro / Ultimate v4.3.6 (current version). The vulnerabilities are located in the main executeabels of the software. Exploitation of the local buffer overflow vulnerability requires a local system access with low user interaction. Successful exploitation of the vulnerability can lead to system compromise.
This module exploits a vulnerability in the XSL parser of the XSL Content Portlet. When Tomcat is present, arbitrary code can be executed via java calls in the data fed to the Xalan XSLT processor. If XSLPAGE is defined, the user must have rights to change the content of that page (to add a new XSL portlet), otherwise it can be left blank and a new one will be created. The second method however, requires administrative privileges.
This module can be used to execute a payload on LANDesk Lenovo ThinkManagement Suite 9.0.2 and 9.0.3. The payload is uploaded as an ASP script by sending a specially crafted SOAP request to "/landesk/managementsuite/core/core.anonymous/ServerSetup.asmx", via a "RunAMTCommand" operation with the command '-PutUpdateFileCore' as the argument. After execution, the ASP script with the payload is deleted by sending another specially crafted SOAP request to "WSVulnerabilityCore/VulCore.asmx" via a "SetTaskLogByFile" operation.