header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

WSO2 Carbon v4.4.5 Local File Inclusion

An authenticated user can download configuration files in the filesystem via downloadArchivedLogFiles operation in LogViewer admin service. The request to the admin service accepts a file path relative to the carbon log file directory (i.e. <WSO2_PRODUCT_HOME>/repository/logs) hence can access any file in the file system.

WSO2 Identity Server v5.1.0 XML External Entity

WSO2IS XML parser is vulnerable to XXE attack in the XACML flow, this can be exploited when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack leads to the disclosure and exfiltration of confidential data and arbitrary system files, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located (localhost), and other system impacts.

Zabbix 3.0.3 SQL Injection Vulnerability

Zabbix 2.2.x, 3.0.x and trunk suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the toggle_ids array in the latest.php page. By exploiting this SQL injection vulnerability, an authenticated attacker (or guest user) is able to gain full access to the database. This would allow an attacker to escalate their privileges to a power user, compromise the database, or execute commands on the underlying database operating system. Although the attacker needs to be authenticated in general, the system could also be at risk if the adversary has no user account. Zabbix offers a guest mode which provides a low privileged default account for users without password. If this guest mode is enabled, the SQL injection vulnerability can be exploited unauthenticated.

Samsung Smart Camera Exploit

This exploit is used to change the web and root passwords of Samsung Smart Camera using the unauthenticated vulnerability found by zenofex. The exploit uses command injection to run a command on the device and convert a normal command into one using bash brace expansion. It then uses HTTP digest auth for urllib2 and uses sed to search and replace the old for new hash in the passwd.

FreePBX 13 remote root 0day

A vulnerability in FreePBX 13 and 14 allows an unauthenticated attacker to execute arbitrary code as root. This vulnerability is due to a lack of input validation in the System Recordings Module versions 13.0.1beta1 - 13.0.26. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server.

Recent Exploits: