FiberHome routers are susceptible to local file inclusion in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
An active network attacker (MiTM) can achieve remote code execution on a machine that runs Ikraus Anti Virus. Ikarus AV for windows uses cleartext HTTP for updates along with a CRC32 checksum and an update value for verification of the downloaded files. Also ikarus checks for a update version number which can be incremented to goad the process to update. The update process executable in ikarus called guardxup.exe guardxup.exe, send over port 80, the following request for update: GET /cgi-bin/virusutilities.pl?A=7534ED66&B=6.1.1.0.11.1.256.7601&C=1005047.2013019.2001016.98727&F=4.5.2%3bO=0%3bSP=0&E=WD-194390-VU HTTP/1.1 Accept: */* User-Agent: virusutilities(6.1,0,1005047) Host: updates.ikarus.at Connection: close The server will respond with: HTTP/1.1 200 OK Date: Sun, 23 Oct 2016 04:51:05 GMT Server: Apache/2.4.10 (Debian) mod_perl/2.0.9dev Perl/v5.20.2 Content-Disposition: inline; filename=virusutilities Content-Length: 306 Connection: close Content-Type: text/plain; charset=ISO-8859-1 <url> full http://mirror04.ikarus.at/ikarus/update/virusutilities.exe crc32 0x7534ED66 version 6.1.1.0.11.1.256.7601 </url>
A Use-after-free vulnerability was found in the Linux kernel's Netlink socket subsystem – XFRM. Netlink is used to transfer information between the kernel and user-space processes. It consists of a standard sockets-based interface for user space processes and an internal kernel API for kernel modules.
Trustwave SWG allows remote attackers to send to the SWG product a SSH key that will be used by the SWG product as the SSH key to logon to the device. This allows unauthenticated user to send a POST request to /sendKey which will add the supplied ssh key to Trustwave SWG, which we can use it to login to the device.
By enabling searches across a wide variety of sources, Oracle's InQuira knowledge management products offer simple and convenient ways for users to access knowledge that was once hidden in the myriad systems, applications, and databases used to store enterprise content. The vulnerable code can be found in /imws/Result.jsp which when calls, can be used to access an XML from a third-party server, this third-party server which can be under our control can be used to reference files locally present on the victim's server. To exploit the vulnerability, we will run the following 5 steps (the first 2 need to be run in the background): 'Malicious' XML External Entity (XXE) server, Listener for the gopher protocol, Attacker who steal the 'custom.xml' file, Decrypt/crack the encrypted AES password, Shell on the machine.
This exploit is used to gain remote code execution on HiSilicon DVR devices. It uses a stack overflow vulnerability to gain access to the device and then uses a connectback shell to gain access to the device. It also has the option to make the shell persistent by restarting the DVR app automatically.
A vulnerability was discovered in Dahua DVR/NVR/IPC and possible all their clones. It allows an attacker to remotely download the full user database with all credentials and permissions, choose whatever admin user, copy the login names and password hashes, and use them as source to remotely login to the Dahua devices.
Vivotek IP Cameras are vulnerable to a remote stack overflow vulnerability. The sta.htm page is vulnerable to a stack overflow, which can be triggered by sending a crafted POST request. The vulnerability can be used to execute arbitrary code on the device.
A remote code execution vulnerability exists in Vitek CCTV cameras due to improper validation of user-supplied input. An attacker can send a specially crafted HTTP request to the vulnerable device to execute arbitrary code on the system. Additionally, an attacker can send a specially crafted HTTP request to the vulnerable device to disclose sensitive information such as firmware version, model name, MAC address, IP address, subnet mask, default gateway, DNS server, system time, system name, system location, admin name, admin password, user name, and user password.
A vulnerability in Uniview allows an attacker to remotely execute commands and export config without authentication. The attacker can send a malicious payload to the Uniview device via a specially crafted HTTP request. This payload will be executed on the device, allowing the attacker to gain access to the device and its configuration.