The vulnerability exists in the roomtype-details.php file, which is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameter 'tid' in the URL.
WP Email Users is vulnerable to SQL Injection due to the $_REQUEST['edit'] parameter being escaped incorrectly. An attacker can exploit this vulnerability by sending a malicious request to the admin-ajax.php page with a crafted filetitle parameter.
An SQL Injection vulnerability in Maian Weblog allows attackers to read arbitrary data from the database.
An SQL Injection vulnerability in My Photo Gallery allows attackers to read arbitrary administrator data from the database.
An integer overflow vulnerability exists in the Palo Alto Networks Terminal Services Agent driver (panta.sys) version 6.0.7.0. The vulnerability is caused by a lack of proper validation of user-supplied input when allocating memory. An attacker can exploit this vulnerability by supplying a specially crafted input to the driver, resulting in an integer overflow, which can be used to execute arbitrary code in the context of the kernel.
This module requires the user to have access to the 'User' account (Default User:123) in the Polycom VoIP phone's web interface. The user can use the following steps to escalate privileges and become the Admin user to reveal menu items internal IP addresses and account information. Login with the 'User' Account. Navigate to Settings > Change Password. Fill in 'Old Password' with the current 'User' password. Fill in 'New Password' with the new 'Admin' account password, and confirm. Using a live HTML editor, inspect the old password field. Change the name field to '120'. Click 'Save'. An error will be shown on screen but you can now log into the Admin account with the new password.
OpenSSH 6.8-6.9 is vulnerable to a local privilege escalation vulnerability due to a race condition in the PTY allocation code. This vulnerability allows a local user to gain root privileges. The vulnerability was discovered by Jann Horn and was assigned CVE-2015-6565.
This is a heads up for a trivial systemd local root exploit, that was silently fixed in the upstream git as: commit 06eeacb6fe029804f296b065b3ce91e796e1cd0e. The analysis says that is a 'possible DoS', but its a local root exploit indeed. Mode 07777 also contains the suid bit, so files created by touch() are world writable suids, root owned. Such as /var/lib/systemd/timers/stamp-fstrim.timer thats found on a non-nosuid mount. This is trivially exploited by something like: http://www.halfdog.net/Security/2015/SetgidDirectoryPrivilegeEscalation/CreateSetgidBinary.c with minimal changes, so no PoC is provided. The bug was possibly introduced via: commit ee735086f8670be1591fa9593e80dd60163a7a2f. We believe that this mostly affects v228 of systemd, but its recommended that distributors cross-check their systemd versions for vulnerable touch_*() functions.
This exploit allows an attacker to read arbitrary files on the TM RG4332 Wireless Router. By sending a specially crafted HTTP request, an attacker can traverse the directory structure of the router and read any file on the system. This vulnerability is due to insufficient input validation of the 'getpage' parameter in the webproc CGI script.
An attacker can bypass authentication by entering any username and setting the password to 'or''=' and hitting enter.