This module exploits a command injection flaw found in the get_log_line function found within Util.pm. The vulnerability is triggered due to an unsanitized $r_file parameter passed to a string which is then executed by the system.
This module exploits a command injection vulnerability found within the sync_rserver function in Util.pm. The vulnerability is triggered due to an incomplete blacklist during the parsing of the $uuid parameter. This allows for the escaping of a system command allowing for arbitrary command execution as root.
This module exploits a directory traversal vulnerability found in Carel Pl@ntVisor <= 2.4.4. The vulnerability is triggered by sending a specially crafted GET request to the victim server.
This module exploits a directory traversal vulnerability found in Carlo Gavazzi Powersoft <= 2.1.1.1. The vulnerability is triggered when sending a specially crafted GET request to the server. The location parameter of the GET request is not sanitized and the sendCommand.php script will automatically pull down any file requested.
This module exploits a file upload vulnerability found within Cloudview NMS < 2.00b. The vulnerability is triggered by sending specialized packets to the server with directory traversal sequences (..@ in this case) to browse outside of the web root.
This module exploits a fileupload vulnerability found in EMC Connectrix Manager Converged Network Edition <= 11.2.1. The file upload vulnerability is triggered when sending a specially crafted filename to the FileUploadController servlet. This allows the attacker to upload a malicious jsp file to anywhere on the remote file system.
This module exploits a file upload vulnerability found in EMC Connectrix Manager Converged Network Edition <= 11.2.1. The file upload vulnerability is triggered when sending a specially crafted filename to the FileUploadController servlet found within the Inmservlets.war archive. This allows the attacker to upload a specially crafted file which leads to remote code execution in the context of the server user.
This module exploits a stack based buffer overflow found in Fatek Automation PLC WinProladder v3.11 Build 14701. The vulnerability is triggered when a client connects to a listening server. The client does not properly sanitize the length of the received input prior to placing it on the stack.
This module exploits a flaw found in Indusoft Web Studio <= 7.1 before SP2 Patch 4. This specific flaw allows users to browse outside of the webroot to download files found on the underlying system.
This module exploits a command injection vulnerability found in Infinite Automation Systems Mango Automation v2.5.0 - 2.6.0 beta (builds prior to 430). It attempts to login with the provided credentials and then execute the command specified in the CMD option.