header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Telesquare SKT LTE Router SDT-CS3B1 CSRF System Command Execution

The router suffers from authenticated arbitrary system command execution. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Easy!Appointments v1.2.1 Multiple Stored XSS Vulnerabilities

The application suffers from multiple stored and reflected XSS vulnerabilities. The issues are triggered when an unauthorized input passed via multiple POST and GET parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Xerox DC260 EFI Fiery Controller Webtools 2.0 Arbitrary File Disclosure

Input passed thru the 'file' GET parameter in 'forceSave.php' script is not properly sanitized before being used to read files. This can be exploited by an unauthenticated attacker to read arbitrary files on the affected system.

PS4 4.05 Kernel Exploit

This project provides a full implementation of the 'namedobj' kernel exploit for the PlayStation 4 on 4.05. It will allow you to run arbitrary code as kernel, to allow jailbreaking and kernel-level modifications to the system. This exploit does include a loader that listens for payloads on port 9020 and will execute them upon receival.

Sendroid – Bulk SMS Portal, Marketing Script( 5.0.0 – 6.5.0 ) – SQL Injection

The software suffers from a SQL Injection vulnerability in the '/API/index.php?action=compose&username=sender&api_key=sdsd&sender' endpoint. An attacker can exploit this vulnerability to gain access to the admin email and password.

Recent Exploits: