header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Xion Audio Player 1.0.127 (.aiff) Denial of Service Vulnerability

Xion Audio Player 1.0.127 is vulnerable to a denial of service attack when a malicious .aiff file is opened. The malicious file contains a FORM header followed by a AIFFCOMM header and an 'A' character. When the file is opened, the program crashes due to an access violation while writing to 00000020.

Sysax Multi Server <= 5.57 Directory Traversal Tool (Post Auth)

Sysax Multi Server version 5.57 and prior is vulnerable to a post-authentication directory traversal vulnerability. An attacker can exploit this vulnerability to traverse the directory structure and access sensitive files on the server.

Simple PHP Agenda <= 2.2.8 CSRF (Add Admin - Add Event)

Simple Php Agenda 2.2.8 (and lower) is affected by a CSRF Vulnerability which allows an attacker to add a new administrator, delete an existing administrator, create/delete a new event and change any other parameters. In this document, the author demonstrates how to add a new administrator, delete an existing administrator, add a new event, and delete an existing event.

BlazeVideo HDTV Player 6.6 Professional SEH&DEP&ASLR

This exploit is for BlazeVideo HDTV Player 6.6 Professional. It is a buffer overflow vulnerability that can be exploited by sending a maliciously crafted packet to the vulnerable application. The exploit will overwrite the SEH and DEP registers and bypass ASLR. It will then execute a shellcode to gain remote access to the system.

Buddypress plugin of WordPress remote SQL Injection

A remote SQL injection vulnerability was discovered in the Buddypress plugin of Wordpress. An attacker could exploit this vulnerability by sending a specially crafted HTTP POST request to the wp-load.php file, containing malicious SQL code in the action parameter. This could allow the attacker to execute arbitrary SQL commands on the vulnerable system.

Woltlab Burning Board 2.2 / 2.3 [WN]KT KickTipp 3.1 remote SQL Injection

[WN]KT KickTipp 3.1 is a Addon for the Woltlab Burning Board 2.2 / 2.3.Web Application for Forum Systems.In this Addon we found a remote SQL Injection vulnerability in the kt_main.php file.The Vulnerability is a hight risk and not fixed from the coder.You must login for the remote SQL injection by the most Systems.

Recent Exploits: