header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

VX Search Enterprise v9.7.18 Import Local Buffer Overflow Vuln.

VX Search Enterprise v9.7.18 is vulnerable to a buffer overflow vulnerability when importing a maliciously crafted XML file. By sending a specially crafted XML file, an attacker can cause a buffer overflow, which can be used to execute arbitrary code. The vulnerability is caused by the lack of proper validation of user-supplied input when importing an XML file.

Create a bind shell on an unpatched OfficeJet 8210

This exploit uses a script to profile.d and reboot the device. When it comes back online then nc to port 1270. The script is sent to the device using the PJL FSDOWNLOAD command. The script is then queried using the PJL FSQUERY command. Finally, the SNMP SET command is used to reboot the device.

Missing bounds-checking in AVI stream parsing

When parsing AVI files, CAVIFileParser uses the stream count from the AVI header to allocate backing storage for storing metadata about the streams (member variable m_aStream). However, the number of stream headers we parse is never validated against this allocation size during parsing, so we can write further metadata past the end of this buffer by constructing a file which contains more stream headers than expected. Several of the values that we can get written out of bounds are pointers to controlled data, which is an interesting exploitation primitive.

EFS Web Server 7.2 POST HTTP Request Buffer Overflow

Easy File Sharing Web Server 7.2 is vulnerable to a buffer overflow vulnerability when handling a maliciously crafted POST request. This can be exploited to execute arbitrary code by sending a specially crafted HTTP request containing an overly long string in the 'Email' parameter.

Nuevo mailer version <= 6.0 SQL Injection

Nuevo mailer version 6.0 and below is vulnerable to SQL injection. The vulnerable script is rdr.php and the vulnerable parameter is r. The proof of concept is to send a request to the vulnerable script with the vulnerable parameter and a malicious payload. For example, https://vulnerable_site.com/inc/rdr.php?r=69387c602c1056c556%20and%20sleep(10)--+

Recent Exploits: