This module exploits a vulnerability in the 'proc_deutf()' function defined in /includes/functions_vbseocp_abstract.php. User input passed through 'char_repl' POST parameter isn't properly sanitized before being used in a call to preg_replace() function which uses the 'e' modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP's complex curly syntax.
This module exploits a stack buffer overflow in HP Diagnostics Server magentservice.exe service. By sending a specially crafted packet, an attacker may be able to execute arbitrary code. Originally found and posted by AbdulAziz Harir via ZDI.
The vulnerability exists in Peel SHOPPING version 2.8 and version 2.9. It allows attackers to inject malicious XSS and SQL payloads via the 'motclef' parameter in the 'recherche.php' script, the 'id' parameter in the 'tva.php' script, and the 'index.php' script.
This module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.50. This issue was fixed in 5.52. You must have valid credentials to trigger the vulnerability. Your credentials must also have the create folder permission and the HTTP option has to be enabled. This module will log into the server, get your a SID token and then proceed to exploit the server. Successful exploits result in LOCALSYSTEM access. This exploit works on XP and 2003.
phplist version 2.10.9 is vulnerable to CSRF and XSS attacks. An attacker can exploit this vulnerability by crafting a malicious HTML page with a form that contains hidden input fields with values that can be used to add an admin account. The attacker can also exploit this vulnerability by sending a post request with a malicious XSS payload in the 'testtarget' parameter.
A CSRF vulnerability exists in VR GPub 4.0 which allows an attacker to add an admin account with the credentials of their choice. An attacker can craft a malicious HTML page containing a form with the necessary parameters and submit it to the vulnerable application. This will add an admin account with the credentials specified in the form.
The WordPress 'setup-config.php' installation page allows users to install WordPress in local or remote MySQL databases. This typically requires a user to have valid MySQL credentials to complete. However, a malicious user can host their own MySQL database server and can successfully complete the WordPress installation without having valid credentials on the target system. After the successful installation of WordPress, a malicious user can inject malicious PHP code via the WordPress Themes editor. In addition, with control of the database store, malicious Javascript can be injected into the content of WordPress yielding persistent Cross Site Scripting.
The web application penetration test uncovered several deficiencies in the security structure of the WebNetwork6 private/hybrid cloud solution. Six stored Cross Site Scripting (XSS) Zero Day vulnerabilities and one Cross Site Request Forgery (CSRF) Zero Day vulnerabilities were discovered in the WebNetwork6 product.
A remote sql injection vulnerability is detected on the new SpamTitan Application v5.08.x The vulnerabilty allows an attacker to inject/execute own sql commands on the affected application dbms. The vulnerability is located in the `/admin/user_list.php` file with the `user_id` parameter.
Restricted access to this script isn't properly realized, so an attacker might be able to upload arbitrary files containing malicious PHP code due to the lack of a proper file extension check.