WordPress plugin Users Ultra Plugin suffers for an unrestricted file upload vulnerability. Any user (registered or not) can exploit a misbehavior of the plugin in order to upload csv files to the infected website. Although the plugin checks file extension using an extensions white-list (in this case only csv files are white-listed), no other checks (mime, size etc) are taking place. This alone can expose the infected website to a variety of attacks.
This module exploits an arbitrary file upload vulnerability found within the Up.Time monitoring server 7.2 and below. A malicious entity can upload a PHP file into the webroot without authentication, leading to arbitrary code execution.
This exploit allows an attacker to execute arbitrary code on a vulnerable XCart 5.2.6 installation. An admin account is required to use this exploit. The exploit works by logging in to the admin panel, then uploading a malicious PHP file to the server. The malicious file contains a passthru command, which allows the attacker to execute arbitrary code on the server. The exploit was discovered by Curesec GmbH.
An exploit for ClipperCMS 1.3.0 Code Execution vulnerability. An account is required with rights to file upload (eg a user in the Admin, Publisher, or Editor role). The server must parse htaccess files for this exploit to work.
Have come across 1 security issue in DGL5500 firmware which allows an attacker on wireless LAN to exploit buffer overflow vulnerabilitiy in hnap functionality. Does not require any authentication and can be exploited on WAN if the management interface is exposed.
An unauthenticated attacker can exploit buffer overflows in authentication and HNAP functionalities by running the exploit at least 200-500 times to bypass ASLR on ARM based devices. The exploit works as the buffer overflow happens in a separate process than the web server which does not allow the web server to crash and hence the attacker wins.
The buffer overflow exploit allows an attacker on wireless LAN and possibly WAN network to execute command injection and buffer overflow attack against the wireless router. The buffer overflow does not have a payload at this time, however if you watch the exploit in a debugger, then it can be clearly seen that the payload uses ROP techniques to get to stack payload which is a bunch of C's for now on the stack. It can be replaced with any payload that works on MIPS little endian architecture.
Have come across 2 security issue in DIR866L firmware which allows an attacker on wireless LAN to exploit buffer overflow vulnerabilities in hnap and send email functionalities. An attacker needs to be on wireless LAN or management interface needs to be exposed on Internet to exploit HNAP vulnerability but it requires no authentication. The send email buffer overflow does require the attacker to be on wireless LAN or requires to trick administrator to exploit using XSRF.
Two buffer overflows in authentication and HNAP functionalities of DIR-890L/R can be exploited by an unauthenticated attacker. The attacker can be on wireless LAN or WAN if the management interface is exposed to attack directly or using XSRF if not exposed. The exploit needs to be run at least 200-500 times to bypass ASLR on ARM based devices. The buffer overflow happens in a separate process than the web server which does not allow the web server to crash and hence the attacker wins.
DIR-815,850L and most of Dlink routers are susceptible to this flaw. This allows to perform command injection using SSDP packets and on UDP. So no authentication required. Just the fact that the attacker needs to be on wireless LAN or be able to fake a request coming from internal wireless LAN using some other mechanism.