FileRun <= 2017.09.18 is vulnerable to Blind SQL Injection. This PoC exploits the vulnerability by sending a crafted HTTP request with a valid cookie to the target server. The exploit is successful when the response contains the string '<th>Name</th>' which indicates that the injection was successful.
Dup Scout Enterprise v10.0.18 is vulnerable to a buffer overflow vulnerability in the "Import Command" feature. An attacker can exploit this vulnerability by crafting a malicious XML file and sending it to the application. When the application parses the malicious XML file, a buffer overflow occurs, which can be used to execute arbitrary code on the target system.
Remote unauthenticated attackers that can make connection the TrendMicro OfficeScan XG application targeting the 'cgiShowClientAdm.exe' process can cause memory corruption issues.
A SQL injection vulnerability exists in Easy Blog PHP Script v1.3a, which allows an attacker to inject malicious SQL queries via the 'id' parameter. An attacker can exploit this vulnerability to gain access to sensitive information from the database.
DiskBoss Enterprise v8.4.16 is vulnerable to a buffer overflow vulnerability in the "Import Command" feature. An attacker can exploit this vulnerability by creating a malicious XML file and selecting it in the "Import Command" feature. This will cause a buffer overflow and allow the attacker to execute arbitrary code on the target system.
DiskBoss Enterprise v8.4.16 is vulnerable to a local buffer overflow vulnerability. By sending a specially crafted string of 1312 A characters followed by 4 B characters and 500 D characters, an attacker can overwrite the EIP register and execute arbitrary code.
An authentication bypass vulnerability exists in Intelbras WRN 150 devices. An attacker can exploit this vulnerability to download the configuration file without authentication by sending a specially crafted HTTP request with a valid cookie.
Host header injection issue as "db_controller.php" relies on $_SERVER['HTTP_HOST'] which can be spoofed by client, instead of $_SERVER['SERVER_NAME']. In environments where caching is in place by making HTTP GET request with a poisoned HOST header webpages can potentially render arbitrary links that point to a malicious website.
Unauthorized LAN attackers that can reach the OfficeScan XG application can make arbitrary HTTP requests to external and internal servers. Abusing a Server Side Request Forgery flaw in the "help_Proxy.php" functionality.
Remote unauthenticated attackers who reach the TrendMicro OfficeScan XG application can query the networks NT domains. NT enumeration is leaked by the web interface when it should not do so. Remote unauthenticated attackers that can connect to TrendMicro OfficeScan XG application can query the PHP version and modules. In 'analyzeWF.php' get_loaded_extensions() and phpversion() calls are made without session or authentication check.