header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

BASE 1.4.5 SQL Injection Vulnerability

BASE Snort Analysis Front-end is vulnerable to SQL injection in the parameters ip_addr[0][1], ip_addr[0][2], and ip_addr[0][9]. An attacker can exploit this vulnerability by sending a malicious payload in the vulnerable parameters. The proof-of-concept URL provided shows an example of exploiting this vulnerability.

GAzie <= 5.20 Cross Site Request Forgery

A Cross Site Request Forgery vulnerability exists in GAzie <= 5.20. An attacker can craft a malicious form and submit it to the vulnerable application, which can lead to unintended actions being performed on behalf of the authenticated user. This can be used to modify the application's data, such as changing user credentials, or to perform administrative actions.

Buffer Overflow Vulnerability in EDBoard

A buffer overflow vulnerability exists in EDBoard, a software developed by EdrawSoft. The vulnerability is caused due to a boundary error when handling the LicenseName argument of the Invoke_Unknown method of the EDBoard.ocx ActiveX control. By supplying a specially crafted argument, a remote attacker could overflow a buffer and execute arbitrary code on the system.

PHP 5.4.0RC6 *64 bit* Code Execution Vulnerability

This script generates a POST header that makes PHP 5.4.0RC6 *64 bit* try to execute code at 0x1111111111111111. PHP 5.3.9 requires you to know the address of a writable address filled with NULL. 32bit requires you to create a fake 32bit Hashtable instead of a 64bit one. Because this vulnerability also allows leaking memory addresses ASLR can be 'semi'-defeated. This means around 4000 tries = 4000 requests = 4000 crashes are enough to bruteforce code addresses to execute arbitrary code despite ASLR/NX better exploit might be possible after deeper research + heap massage. This specific attack only works if there is no Suhosin-Patch -> RHEL, CentOS.

OSCommerce v3.0.2 – Persistent Cross Site Vulnerability

Multiple persistant cross site vulnerabilities are detected on the OSCommerce v3.0.2. The bug allows remote attacker to implement malicious script code on the application side. Successful exploitation of the vulnerability allows an attacker to manipulate specific modules & can lead to session hijacking (user/mod/admin).

NetSarang Xlpd Printer Daemon Denial of Service Vulnerability

NetSarang Xlpd Printer Daemon version 4 is prone to a denial of service vulnerability. The vulnerability is caused due to improper validation of malicious LPD request sent to printer daemon, which allows remote attackers to crash the service.

Recent Exploits: