Multiple persistence Cross-Site Scripting vulnerabilities are present in Apache Struts, as it fails to sanitise user-supplied input. Input passed via the 'name' and 'lastName' parameter in '/struts2-showcase/person/editPerson.action' is not properly verified before it is returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of a vulnerable site. Input passed via the 'clientName' parameter in '/struts2-rest-showcase/orders' action is not properly verified before it is returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of a vulnerable site. Input passed via the 'name' parameter in '/struts-examples/upload/upload-submit.do?queryParam=Successful' action is not properly verified before it is returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of a vulnerable site. Input passed via the 'name' parameter in '/struts2-showcase/fileupload/doUpload.action' action is not properly verified before it is returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of a vulnerable site.
Input passed via the 'comment' to 1)/Blog/MyFirstBlog.txt, 2)/Blog/AboutSomething.txt pages are not properly verified, which allows remote attackers to inject arbitrary script code.
This module exploits a stack based buffer overflow found in the SNMP NetDBServer service of Sunway Forcecontrol <= 6.1 sp3. The overflow is triggered when sending an overly long string to the listening service on port 2001.
MailEnable Professional and Enterprise versions are prone to cross-site scripting vulnerabilities as the user-supplied input received via "Username" parameter of "ForgottonPassword.aspx" page is not properly sanitized. A specially crafted URL which a user clicks could gain access to the users cookies for webmail or execute other malicious code in users browser in context of the domain in use.
This exploit is a buffer overflow vulnerability in the WebKit normalize function. It was tested on Moto Droidx2 running 2.2 and 2.3, as well as a 2.1-2.3 emulator. The exploit uses a spray of 0x52 bytes followed by a shellcode to gain remote access to the device. The shellcode contains the IP address and port of the attacker's machine.
High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in SiT! Support Incident Tracker, which can be exploited to perform SQL injection, cross-site scripting, cross-site request forgery attacks. Input passed via the 'start' GET parameter to /portal/kb.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Input passed via the 'contractid' GET parameter to contract_add_service.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Input passed via the 'mode' GET parameter to contact_support.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user browser session in context of affected website. Input passed via the 'contractid' GET parameter to contract_add_service.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user browser session in context of affected website. Input passed via the 'user' GET parameter to edit_backup_users.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user browser session in context of affected website.
Go to http://server/create_ticket.php, fill all input fields and click on Submit Ticket. Click on the View Ticket and you should go to the link like http://server/view_ticket.php?email=[Your Email]&id=1. You see Send Message box, write anything there and attach your PHP file in the Upload attachment and click on Send Message. You can see your attachment above like Attachment: shell.php, click on it and you see your PHP code has been runed. For PHP Code Injection vulnerability, go to http://server/signin.php and write your php in input fields like phpi${@print(RedSecurityTEAM)}. For XSS vulnerability, go to http://server/view_ticket.php?email=example@example.com&id="onmouseover=alert(1) bad=" and http://server/kb_search.php?keywords="onmouseover=alert(1) bad="&mode=Search.
This exploit is a buffer overflow vulnerability that allows an attacker to set multiple cookies with a value of up to 819 characters. The malicious cookies are then sent to the server, which can cause a buffer overflow and lead to a denial of service attack. The attacker can also use the cookies to gain access to sensitive information or execute arbitrary code on the server.
The vulnerability exists in the Agent Zone Vastal I-Tech real estate script, which allows an attacker to inject malicious SQL queries via the 'price_from' and 'price_to' parameters in the 'search.php' script. By manipulating these parameters, an attacker can bypass authentication and gain access to sensitive information from the database.
Edraw Office Viewer Component contains a standard ActiveX control that acts as an ActiveX document container for hosting Office documents (including Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Project, and Microsoft Visio documents) in a custom form or Web page. The control is lightweight and flexible, and gives developers new possibilities for using Office in a custom solution. The ActiveX suffers from a buffer overflow vulnerability when parsing large amount of bytes to the FtpUploadFile member in FtpUploadFile() function, resulting memory corruption overwriting severeal registers including the SEH. An attacker can gain access to the system of the affected node and execute arbitrary code.