This module exploits a buffer overflow in the encryption option handler of the Linux BSD-derived telnet service (inetutils or krb5-telnet). Most Linux distributions use NetKit-derived telnet daemons, so this flaw only applies to a small subset of Linux systems running telnetd.
This module exploits weak WebDAV passwords on XAMPP servers. It uses supplied credentials to upload a PHP payload and execute it.
This module exploits a vulnerability in the U3D handling within versions 9.x through 9.4.6 and 10 through to 10.1.1 of Adobe Reader. The vulnerability is due to the use of uninitialized memory. Arbitrary code execution is achieved by embedding specially crafted U3D data into a PDF document. A heap spray via JavaScript is used in order to ensure that the memory used by the invalid pointer issue is controlled.
This bug is triggered when the browser handles a JavaScript 'onLoad' handler in conjunction with an improperly initialized 'window()' JavaScript function. This exploit results in a call to an address lower than the heap. The javascript prompt() places our shellcode near where the call operand points to. We call prompt() multiple times in separate iframes to place our return address. We hide the prompts in a popup window behind the main window. We spray the heap a second time with our shellcode and point the return address to the heap. I use a fairly high address to make this exploit more reliable. IE will crash when the exploit completes. Also, please note that Internet Explorer must allow popups in order to continue exploitation.
The vulnerability exists in the pragyan 2.6.1 version of the software. An attacker can exploit this vulnerability by accessing the http://localhost/Path/cms/modules/article/fckEditor/editor/filemanager/browser/default/frmupload.html URL and uploading a malicious shell.
The persistent input validation vulnerability is located in the `Tine v2.0 Maischa` application. Local attackers are able to manipulate the vulnerable `name` and `description` value of the `Tine v2.0 Maischa` application. The vulnerability can be exploited by local attackers with low user interaction & privileged user account. Successful exploitation of the vulnerability can lead to session hijacking, persistent phishing attacks, persistent external redirects and persistent manipulation of affected or connected module context.
Discovered a vulnerability in wp-autoyoutube, Wordpress Plugin, vulnerability is Blind SQL injection. File: wp-content/plugins/wp-autoyoutube/modules/index.php Exploit: id=-1; or 1=if
A SQL injection vulnerability exists in the view_comments.php file of AIHS (Advanced Image Hosting Script). An attacker can exploit this vulnerability by sending a crafted HTTP request with a malicious SQL query to the vulnerable parameter 'gal' in the view_comments.php file. This can allow the attacker to gain access to the database and extract sensitive information such as usernames and passwords.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XDR decoding of the caller_name field. The XDR decoding routine does not properly validate the length of the field before copying it into a fixed-length buffer. An attacker can leverage this vulnerability to execute arbitrary code under the context of the application.
The Wordpress Age Verification plugin version 0.4 is vulnerable to open redirect. An attacker can craft a malicious URL with a redirect parameter and redirect a victim to a malicious website. This can be done via GET or POST request.