header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

FileRun <=2017.09.18

FileRun <= 2017.09.18 is vulnerable to Blind SQL Injection. This PoC exploits the vulnerability by sending a crafted HTTP request with a valid cookie to the target server. The exploit is successful when the response contains the string '<th>Name</th>' which indicates that the injection was successful.

Dup Scout Enterprise v10.0.18 “Import Command” Buffer Overflow

Dup Scout Enterprise v10.0.18 is vulnerable to a buffer overflow vulnerability in the "Import Command" feature. An attacker can exploit this vulnerability by crafting a malicious XML file and sending it to the application. When the application parses the malicious XML file, a buffer overflow occurs, which can be used to execute arbitrary code on the target system.

DiskBoss Enterprise v8.4.16 “Import Command” Buffer Overflow

DiskBoss Enterprise v8.4.16 is vulnerable to a buffer overflow vulnerability in the "Import Command" feature. An attacker can exploit this vulnerability by creating a malicious XML file and selecting it in the "Import Command" feature. This will cause a buffer overflow and allow the attacker to execute arbitrary code on the target system.

DiskBoss Enterprise v8.4.16 Local Buffer Overflow(PoC)

DiskBoss Enterprise v8.4.16 is vulnerable to a local buffer overflow vulnerability. By sending a specially crafted string of 1312 A characters followed by 4 B characters and 500 D characters, an attacker can overwrite the EIP register and execute arbitrary code.

Autentication Bypass/Config file download – INTELBRAS WRN 150

An authentication bypass vulnerability exists in Intelbras WRN 150 devices. An attacker can exploit this vulnerability to download the configuration file without authentication by sending a specially crafted HTTP request with a valid cookie.

TrendMicro OfficeScan XG Host Header Injection

Host header injection issue as "db_controller.php" relies on $_SERVER['HTTP_HOST'] which can be spoofed by client, instead of $_SERVER['SERVER_NAME']. In environments where caching is in place by making HTTP GET request with a poisoned HOST header webpages can potentially render arbitrary links that point to a malicious website.

TrendMicro OfficeScan XG Server Side Request Forgery

Unauthorized LAN attackers that can reach the OfficeScan XG application can make arbitrary HTTP requests to external and internal servers. Abusing a Server Side Request Forgery flaw in the "help_Proxy.php" functionality.

Unauthorized NT Domain Disclosure & PHP Information Disclosure in TrendMicro OfficeScan

Remote unauthenticated attackers who reach the TrendMicro OfficeScan XG application can query the networks NT domains. NT enumeration is leaked by the web interface when it should not do so. Remote unauthenticated attackers that can connect to TrendMicro OfficeScan XG application can query the PHP version and modules. In 'analyzeWF.php' get_loaded_extensions() and phpversion() calls are made without session or authentication check.

Recent Exploits: