header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

iball Baton 150M Wireless router – Authentication Bypass

Any attacker can escalate his privilege to admin using this vulnerability. To exploit this vulnerability, an attacker needs to navigate to the router's login page which is usually the IPV4 default gateway IP, i.e. 172.20.174.1. Then, the attacker needs to append password.cgi to the URL i.e. http://172.20.174.1/password.cgi. Right-clicking and viewing the source code will disclose the username, password and user role of the admin in the comment section. The attacker can then successfully log in using the disclosed credentials.

Brickcom IP-Camera Remote Credentials and Settings Disclosure

Brickom Cameras allow a low-privilege user to disclose every configuration in the NVRAM, including credentials in clear text, remotely by making a simple requests. This vulnerability, coupled with the fact that there are two default users with known passwords which are rarely modified, allows an attacker to disclose the admin password and latter every config. The most Critical API call is users.cgi?action=getUsers, which provides every user credential. Many other API calls to get information for the WIFI password or FTP credentials, even the whole configuration, are affected depending on the camera model. On the hardware side, the UART console of some models (example: WCB-040Af, with baudrate 38400) is exposed in the PCB and after soldering the corresponding pins and connecting, the resulting shell has root access. A simple NVSHOW command will list every config available in clear text, including credentials.

QNAP Transcode Server Command Execution

This module exploits an unauthenticated remote command injection vulnerability in QNAP NAS devices. The transcoding server listens on port 9251 by default and is vulnerable to command injection using the 'rmfile' command. This module was tested successfully on a QNAP TS-431 with firmware version 4.3.3.0262 (20170727).

PHP Video Battle Script 1.0 – SQL Injection

The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/[SQL].html -1'+uNiOn+SeleCt++0x31,0x32,0x33,0x34,0x35,(Select+export_set(5,@:=0,(select+count(*)from(information_schema.columns)where@:=export_set(5,export_set(5,@,table_name,0x3c6c693e,2),column_name,0xa3a,2)),@,2)),0x37+--+--+-.html http://localhost/[PATH]/videobattle.html?vote=[SQL] http://localhost/[PATH]/videobattle.html?draw=[SQL]

Car or Cab Booking Script – SQL injection login bypass

An attacker is able to inject malicious SQL query to bypass the login page and login as admin of the particular school. The attacker must set the username and password to 'admin' or 1=1 -- - and choose the check box as current and existing user.

D-Link DIR-600 – Authentication Bypass (Absolute Path Traversal Attack)

After Successfully Connected to D-Link DIR-600 Router(FirmWare Version : 2.01), Any User Can Easily Bypass The Router's Admin Panel Just by adding a simple payload into URL. D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.

NethServer 7.3.1611 (create.json) CSRF Create User And Enable SSH Access

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Recent Exploits: