header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Oreans WinLicense v2.1.8.0 XML File Handling Unspecified Memory Corruption

WinLicense is prone to an unspecified memory corruption vulnerability. An attacker can exploit this issue by tricking a victim into opening a malicious XML file to execute arbitrary code and to cause denial-of-service conditions.

Adobe Photoshop 12.1 Tiff Parsing Use-After-Free

Adobe Photoshop is a graphics editing program developed and published by Adobe Systems Incorporated. Adobe's 2003 'Creative Suite' rebranding led to Adobe Photoshop 8's renaming to Adobe Photoshop CS. Thus, Adobe Photoshop CS5 is the 12th major release of Adobe Photoshop. The CS rebranding also resulted in Adobe offering numerous software packages containing multiple Adobe programs for a reduced price. Adobe Photoshop is released in two editions: Adobe Photoshop, and Adobe Photoshop Extended, with the Extended having extra 3D image creation, motion graphics editing, and advanced image analysis features. Adobe Photoshop Extended is included in all of Adobe's Creative Suite offerings except Design Standard, which includes the Adobe Photoshop edition. Alongside Photoshop and Photoshop Extended, Adobe also publishes Photoshop Elements and Photoshop Lightroom, collectively called 'The Adobe Photoshop Family'. In 2008, Adobe released Adobe Photoshop Express, a free web-based image editing tool to edit photos directly on blogs and social networking sites; in 2011 a version was released for the Android operating system and the iOS operating system. Adobe only supports Windows and Macintosh versions of Photoshop, but using Wine, Photoshop CS5 can run well on Linux.

ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet Unauthenticated Remote Directory Traversal Database Backup / auth-conf.xml Disclosure Exploit

DeviceExpert is a web–based, multi vendor network change, configuration and compliance management (NCCCM) solution for switches, routers, firewalls and other network devices. Without prior authentication, it is possible to invoke the ScheduleResultViewer servlet to disclose every file on target system. This can be done through the FileName argument which suffers of a directory traversal vulnerability. auth-conf.xml stores the authentication credentials to the administrative interface (username, hashed password and a salt). It is also possible to backup the MySQL database tables by cycling through subfolders.

LANDesk Lenovo ThinkManagement Suite 9.0.3 Core Server WSVulnerabilityCore.dll SetTaskLogByFile() Remote Arbitrary File Deletion Vulnerability

The mentioned product creates various virtual directories on IIS. Among them the 'WSVulnerabilityCore' one. Without prior authentication / authorization is possible to invoke the 'VulCore.asmx' web service which exposes various functions inside the underlying dlls. By specifying the 'SetTaskLogByFile' operation is possible to delete arbitrary files on the target operating system. The 'filename' argument is used to delete files and suffers of a directory traversal vulnerability, no checks of any kind. To the ManagementSuite foler is possible to write files, so it is possible to delete any file on the target system.

LANDesk Lenovo ThinkManagement Suite 9.0.3 Core Server AMTConfig.Business.dll RunAMTCommand Remote Code Execution Vulnerability

By specifying the 'RunAMTCommand' operation is possible to create arbitrary files inside public virtual directories. This operation supports five arguments: when the 'Command' argument is set ex. to '-PutUpdateFileCore', 'Data2' and 'Data3' are used for file creation. The first one suffers of a directory traversal vulnerability. You are in control of the path, extension and content of the newly created file. Then you can execute arbitrary code by invoking this file.

Recent Exploits: