header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Lotus Notes Diagnostic Tool (nsd.exe) Privelege Escalation

Lotus Notes Diagnostic Tool (nsd.exe) runs under NT Authority/System rights. This can be leveraged to run a program under the System context and elevate local privileges. First you need to execute nsd.exe under the monitor/CLI mode: > nsd.exe -monitor. Next, after NSD finishes loading you can execute any program under the System context. In this example we will execute CMD. nsd> LOAD CMD. You will see that cmd is opened as System now. Also, NSD can be used to attach, kill processes or create memory dumps under the System context.

FineCMS 1.0 Multiple Vulnerabilities

file /application/lib/ajax/get_image.php the $_POST['id'] and $_POST['name'] and $_GET['folder'] without any validated, sanitised or output encoded. The base function for modify the template can modify the filename,this leads to the Arbitrary File Modify, who could allow attacker getshell. All FineCMS use PDO to connect the mysql server, so all the data without any validated, sanitised or output encoded injection database.but in application/core/controller/excludes.php, the website author use mysqli to connect mysql server.the lead SQL injection, who could allow attacker use some payload to get data in database.

initroot: Motorola Bootloader Kernel Cmdline Injection Secure Boot & Device Locking Bypass (CVE-2016-10277)

Vulnerable versions of the Motorola Android Bootloader (ABOOT) allow for kernel command-line injection. Using a proprietary fastboot OEM command, only available in the Motorola ABOOT, an adversary can inject, through USB, a parameter named initrd which allows them to force the Linux kernel to populate initramfs into rootfs from a specified physical address. This can be abused to place a malicious initramfs at a known physical address, named SCRATCH_ADDR, and exploit the vulnerability to gain unconfined root shell. However, the initramfs payload must be re-exploited on every reboot.

Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6

An unauthenticated SQL injection vulnerability was discovered in Huge-IT Portfolio Gallery Plugin v1.0.6. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow an attacker to gain access to the underlying database and potentially gain access to sensitive data.

Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla

An unauthenticated SQL injection vulnerability exists in Huge-IT Catalog v1.0.7 for Joomla. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the vulnerable application. The application is vulnerable to error-based, AND/OR time-based blind, and generic UNION query injection attacks. The back-end DBMS is MySQL and the web server operating system is Linux Debian 8.0 (jessie).

PHP-SecureArea <= v2.7 - SQL Injection

PHP-SecureArea is vulnerable to SQL injection due to lack of input sanitization in the misc.php file. An attacker can exploit this vulnerability by sending a specially crafted POST request to the process.php file with an item_number parameter set to a malicious value.

Invoice Manager v3.1 – Cross site request forgery (Add Admin)

Invoice Manager v3.1 is vulnerable to CSRF attack (No CSRF token in place) which if an admin user can be tricked to visit a crafted URL created by attacker (via spear phishing/social engineering). Once exploited, the attacker can login as the admin using the email and the password in the below exploit.

Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

An unauthenticated SQL injection vulnerability was discovered in Huge-IT Video Gallery v1.0.9 for Joomla. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. The request contains a malicious SQL query in the 'page' and 'galleryid' parameters. This can allow an attacker to execute arbitrary SQL commands on the underlying database.

Recent Exploits: