header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Alienvault OSSIM av-centerd Util.pm sync_rserver Command Execution

This module exploits a command injection vulnerability found within the sync_rserver function in Util.pm. The vulnerability is triggered due to an incomplete blacklist during the parsing of the $uuid parameter. This allows for the escaping of a system command allowing for arbitrary command execution as root.

Carlo Gavazzi Powersoft Directory Traversal

This module exploits a directory traversal vulnerability found in Carlo Gavazzi Powersoft <= 2.1.1.1. The vulnerability is triggered when sending a specially crafted GET request to the server. The location parameter of the GET request is not sanitized and the sendCommand.php script will automatically pull down any file requested.

EMC CMCNE FileUploadController Remote Code Execution

This module exploits a fileupload vulnerability found in EMC Connectrix Manager Converged Network Edition <= 11.2.1. The file upload vulnerability is triggered when sending a specially crafted filename to the FileUploadController servlet. This allows the attacker to upload a malicious jsp file to anywhere on the remote file system.

EMC CMCNE Inmservlets.war FileUploadController Remote Code Execution

This module exploits a file upload vulnerability found in EMC Connectrix Manager Converged Network Edition <= 11.2.1. The file upload vulnerability is triggered when sending a specially crafted filename to the FileUploadController servlet found within the Inmservlets.war archive. This allows the attacker to upload a specially crafted file which leads to remote code execution in the context of the server user.

Fatek Automation PLC WinProladder Stack-based Buffer Overflow

This module exploits a stack based buffer overflow found in Fatek Automation PLC WinProladder v3.11 Build 14701. The vulnerability is triggered when a client connects to a listening server. The client does not properly sanitize the length of the received input prior to placing it on the stack.

Infinite Automation Mango Automation Command Injection

This module exploits a command injection vulnerability found in Infinite Automation Systems Mango Automation v2.5.0 - 2.6.0 beta (builds prior to 430). It attempts to login with the provided credentials and then execute the command specified in the CMD option.

Recent Exploits: