Fork CMS is dedicated to creating a user friendly environment to build, monitor and update websites. Reflected Cross-Site Scripting (XSS) on Admin Panel can be exploited by sending a malicious URL with a script tag containing an alert command. Local File Inclusion (LFI) can be exploited by sending a malicious URL with a file parameter containing a path traversal string.
The vulnerability is caused due to a boundary error within the processing of M3U files. By creating a specially crafted M3U file, an attacker can cause a stack-based buffer overflow, resulting in a denial of service condition.
Multiple File Include Vulnerabilities are detected on Dolibarrs Content Management System v3.2.0 Alpha. The vulnerability allows an attacker (remote) or local low privileged user account to request local web-server or system files. Successful exploitation of the vulnerability results in dbms & application compromise.
This module exploits a vulnerability found in Adobe Flash Player's Flash10u.ocx component. When processing a MP4 file (specifically the Sequence Parameter Set), Flash will see if pic_order_cnt_type is equal to 1, which sets the num_ref_frames_in_pic_order_cnt_cycle field, and then blindly copies data in offset_for_ref_frame on the stack, which allows arbitrary remote code execution under the context of the user. Numerous reports also indicate that this vulnerability has been exploited in the wild.
This module exploits a remote buffer overflow in the Citrix Provisioning Services 5.6 SP1 (without Hotfix CPVS56SP1E043) by sending a malformed packet to the 6905/UDP port. The module has been successfully tested on Windows Server 2003 SP2, Windows 7, and Windows XP SP3.
A critical File Include vulnerability is detected on the Cyberoam Central Console v2.00.2x. The vulnerability allows an attacker to request local system or application files (example:telnet-service jsp). Successful exploitation can result in dbms or service/appliance compromise via file include vulnerability.
A buffer overflow vulnerability exists in TORCS version 1.3.2. An attacker can exploit this vulnerability by creating a template.xml file with malicious code and placing it in the torcs/cars/sc-f1/ directory, replacing sc-f1.xml. When the attacker chooses the car and runs a race, Torcs will crash.
This exploit is a Denial of Service (DoS) attack against the Typsoft FTP Server. The exploit sends a malformed CWD command with a string of 250 '.' characters, which causes the server to crash. The exploit requires a valid username and password to execute.
This exploit allows an attacker to add an admin account to the Flyspray 0.9.9.6 application. The exploit is done by creating a malicious HTML page that contains a form with hidden fields. When the page is loaded, the form is automatically submitted, creating a new admin account with the username 'root' and the password '12345678'.
XRay CMS is vulnerable to a SQL Injection attack which allows authentication bypass into the admins account. If a malicious user supplies ' or 1=1# into the applications user name field they will be logged into the applications admin account.