header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

File Extension Filter Bypass in File Manager Pixie 1.0.4 With Low Privilege

Pixie is a free, open source web application that will help quickly create your own website. It has three types of account privilege for upload: Administrator, Client, and User. Generally, Pixie CMS has restricted extension for file upload and we cannot upload php extension. However, an attacker can bypass this restriction by intercepting the request and changing the filename from “our_shell.jpg” to “our_shell.jpg.php” and writing a shell under the “Content-Type: image/jpeg” perimeter.

Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability

Apache Tomcat is prone to a security-bypass vulnerability. An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks. Apache Tomcat 9.0.0.M1 through 9.0.0.M11, 8.5.0 through 8.5.6, 8.0.0.RC1 through 8.0.38, 7.0.0 through 7.0.72 and 6.0.0 through 6.0.47 are vulnerable. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection

A malicious user may exploit numerous vectors to execute arbitrary commands on the router. An example of an exploit is a reverse shell, which can be used to gain access to the router, as well as a dump password file, which can be used to gain access to the router's credentials.

Membership Formula – Best Membership Site PHP Script – SQL Injection

Login as regular user and send a malicious SQL query to the vulnerable parameter 'order' in the URL http://localhost/[PATH]/members/member.area.directory.php?order=[SQL] to extract sensitive information from the members table such as id, first_name, last_name, email and password.

Javascript (JSON) Information Theft

Attackers can siphon information from Splunk Enterprise if an authenticated Splunk user visits a malicious webpage. Some useful data gained is the currently logged in username and if remote user setting is enabled. After, the username can be use to Phish or Brute Force Splunk Enterprise login. Additional information stolen may aid in furthering attacks. Root cause is the global Window JS variable assignment of config?autoload=1 '$C'.

macOS/IOS: mach_msg: doesn’t copy memory

When sending ool memory via |mach_msg| with |deallocate| flag or |MACH_MSG_VIRTUAL_COPY| flag, |mach_msg| performs moving the memory to the destination process instead of copying it. But it doesn't consider the memory entry object that could resurrect the moved memory. As a result, it could lead to a shared memory race condition. We need specific code that references the memory twice from |mach_msg|. Here's a snippet of such a function |xpc_dictionary_insert|. v14 = strlen(shared_memory); <<-- 1st v15 = _xpc_malloc(v14 + 41); ... strcpy((char *)(v15 + 32), shared_memory); <<-- 2nd If we change the string's length bigger before |strcpy| is called, it will result in a heap overflow. This bug is triggerable from a sandboxed process. The attached PoC will crash diagnosticd(running as root). It requires more than 512MB memory to run.

EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root

This exploit is an unauthenticated SQL injection in EyesOfNetwork 5.1, which allows an attacker to gain remote root access. The exploit is based on a DELETE statement, which is used to delete all entries in the [sessions] table except one. The session_id is then retrieved by using a combination of SLEEP and SUBSTR functions.

Sync Breeze Enterprise 9.5.16 – ‘Import Command’ Buffer Overflow (SEH)

Sync Breeze Enterprise is prone to a buffer overflow vulnerability when handling specially crafted XML files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This vulnerability affects Sync Breeze Enterprise version 9.5.16.

Recent Exploits: