header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Stored Cross Site Scripting (XSS) in Progress Sitefinity CMS 9.2

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Below mentioned input fields aren't properly escaped. This could lead to an XSS attack that could possibly affect administrators, users, editor.

Tiny HTTPd 0.1.0 Local File Traversal

Tiny HTTPd 0.1.0 is vulnerable to Local File Traversal vulnerability. An attacker can exploit this vulnerability to read sensitive files from the server. To exploit this vulnerability, an attacker can send a specially crafted HTTP request containing directory traversal characters (e.g. '../') to the vulnerable server. This will allow the attacker to read sensitive files from the server.

FLIR Systems FLIR Thermal Camera PT-Series (PT-334 200562) Remote Root Exploit

FLIR Camera PT-Series suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exist due to several POST parameters in controllerFlirSystem.php script when calling the execFlirSystem() function not being sanitized when using the shell_exec() PHP function while updating the network settings on the affected device. This allows the attacker to execute arbitrary system commands as the root user and bypass access controls in place.

FoV-1289: Wi-Fi Firmware Backdoor on iPhone 7

This exploit gains code execution on the Wi-Fi firmware on the iPhone 7. It has been tested against the Wi-Fi firmware as present on iOS 10.2 (14C92), but should work on all versions of iOS up to 10.3.3 (included). Upon successful execution of the exploit, a backdoor is inserted into the firmware, allowing remote read/write commands to be issued to the firmware via crafted action frames.

The attached fuzzed MP4 file causes an out-of-bounds memory access when played with Adobe Flash

This vulnerability is an out-of-bounds memory access in Adobe Flash when playing a specially crafted MP4 file. The vulnerability is caused by a lack of proper bounds checking when processing the MP4 file. This can lead to an attacker being able to execute arbitrary code on the affected system.

JitBit HelpDesk <= 9.0.2 Broken Authentication

JitBit HelpDesk version 9.0.2 and prior suffer from a broken authentication vulnerability. An attacker can exploit this vulnerability to gain access to the application and potentially gain access to sensitive data. This vulnerability is due to the application not properly validating user credentials. An attacker can exploit this vulnerability by sending a specially crafted request to the application.

Recent Exploits: