Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Below mentioned input fields aren't properly escaped. This could lead to an XSS attack that could possibly affect administrators, users, editor.
Tiny HTTPd 0.1.0 is vulnerable to Local File Traversal vulnerability. An attacker can exploit this vulnerability to read sensitive files from the server. To exploit this vulnerability, an attacker can send a specially crafted HTTP request containing directory traversal characters (e.g. '../') to the vulnerable server. This will allow the attacker to read sensitive files from the server.
FLIR suffers from an unauthenticated and unauthorized live stream disclosure. An attacker can access the live stream of the camera without authentication.
FLIR utilizes hard-coded credentials within its Linux distribution image. These sets of credentials are never exposed to the end-user and cannot be changed through any normal operation of the camera.
FLIR Camera PT-Series suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exist due to several POST parameters in controllerFlirSystem.php script when calling the execFlirSystem() function not being sanitized when using the shell_exec() PHP function while updating the network settings on the affected device. This allows the attacker to execute arbitrary system commands as the root user and bypass access controls in place.
This exploit gains code execution on the Wi-Fi firmware on the iPhone 7. It has been tested against the Wi-Fi firmware as present on iOS 10.2 (14C92), but should work on all versions of iOS up to 10.3.3 (included). Upon successful execution of the exploit, a backdoor is inserted into the firmware, allowing remote read/write commands to be issued to the firmware via crafted action frames.
This vulnerability is an out-of-bounds memory access in Adobe Flash when playing a specially crafted MP4 file. The vulnerability is caused by a lack of proper bounds checking when processing the MP4 file. This can lead to an attacker being able to execute arbitrary code on the affected system.
This exploit is a buffer overflow exploit for Windows XP SP3. It uses an egghunter to search for a specific egg, followed by a jump to ESP and a NOP sled. The payload is a reverse TCP shellcode that connects to a specified IP address and port.
JitBit HelpDesk version 9.0.2 and prior suffer from a broken authentication vulnerability. An attacker can exploit this vulnerability to gain access to the application and potentially gain access to sensitive data. This vulnerability is due to the application not properly validating user credentials. An attacker can exploit this vulnerability by sending a specially crafted request to the application.
This vulnerability is an out-of-bounds memory access in Adobe Flash Player. It is triggered when a specially crafted MP4 file is played in Flash Player. This can lead to arbitrary code execution.