header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Fork CMS v.3.2.4 – Multiple Vulnerabilities

Fork CMS is dedicated to creating a user friendly environment to build, monitor and update websites. Reflected Cross-Site Scripting (XSS) on Admin Panel can be exploited by sending a malicious URL with a script tag containing an alert command. Local File Inclusion (LFI) can be exploited by sending a malicious URL with a file parameter containing a path traversal string.

Dolibarr CMS v3.2.0 Alpha – File Include Vulnerabilities

Multiple File Include Vulnerabilities are detected on Dolibarrs Content Management System v3.2.0 Alpha. The vulnerability allows an attacker (remote) or local low privileged user account to request local web-server or system files. Successful exploitation of the vulnerability results in dbms & application compromise.

Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow

This module exploits a vulnerability found in Adobe Flash Player's Flash10u.ocx component. When processing a MP4 file (specifically the Sequence Parameter Set), Flash will see if pic_order_cnt_type is equal to 1, which sets the num_ref_frames_in_pic_order_cnt_cycle field, and then blindly copies data in offset_for_ref_frame on the stack, which allows arbitrary remote code execution under the context of the user. Numerous reports also indicate that this vulnerability has been exploited in the wild.

Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020000 Buffer Overflow

This module exploits a remote buffer overflow in the Citrix Provisioning Services 5.6 SP1 (without Hotfix CPVS56SP1E043) by sending a malformed packet to the 6905/UDP port. The module has been successfully tested on Windows Server 2003 SP2, Windows 7, and Windows XP SP3.

Cyberoam Central Console v2.00.2 – File Include Vulnerability

A critical File Include vulnerability is detected on the Cyberoam Central Console v2.00.2x. The vulnerability allows an attacker to request local system or application files (example:telnet-service jsp). Successful exploitation can result in dbms or service/appliance compromise via file include vulnerability.

TORCS <= 1.3.2 buffer overflow /SAFESEH evasion

A buffer overflow vulnerability exists in TORCS version 1.3.2. An attacker can exploit this vulnerability by creating a template.xml file with malicious code and placing it in the torcs/cars/sc-f1/ directory, replacing sc-f1.xml. When the attacker chooses the car and runs a race, Torcs will crash.

Flyspray 0.9.9.6 CSRF Vulnerability

This exploit allows an attacker to add an admin account to the Flyspray 0.9.9.6 application. The exploit is done by creating a malicious HTML page that contains a form with hidden fields. When the page is loaded, the form is automatically submitted, creating a new admin account with the username 'root' and the password '12345678'.

Recent Exploits: