header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

EyeLock nano NXT 3.5 Remote Root Exploit

This exploit is for EyeLock nano NXT 3.5, a miniaturized iris-based recognition system capable of providing real-time identification, both in-motion and at a distance. The exploit allows for remote root access to the device, allowing an attacker to gain full control of the system.

EyeLock nano NXT 3.5 Local File Disclosure Vulnerability

Nano NXT suffers from a file disclosure vulnerability when input passed thru the 'path' parameter to 'logdownload.php' script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources.

EyeLock Myris 3.3.2 SDK Service Unquoted Service Path Privilege Escalation

The application suffers from an unquoted search path issue impacting the service 'MyrisService' for Windows deployed as part of Myris solution. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user’s code would execute with the elevated privileges of the application.

vBulletin <= 5.2.2 Preauth Server Side Request Forgery (SSRF) Vulnerability

vBulletin forum software is affected by a SSRF vulnerability that allows unauthenticated remote attackers to access internal services (such as mail servers, memcached, couchDB, zabbix etc.) running on the server hosting vBulletin as well as services on other servers on the local network that are accessible from the target. This advisory provides a PoC exploit that demonstrates how an unauthenticated attacker could perform a port scan of the internal services as well as execute arbitrary system commands on a target vBulletin host with a locally installed Zabbix Agent monitoring service.

Nagios Network Analyzer v2.2.1 Multiple CSRF Vulnerability

Nagios NA has multiple CSRF vectors, allowing unauthorized commands to be transmitted from a user that the website trusts if that user is authenticated and visits a malicious webpage or clicks a attacker supplied link. The Nagios system can be compromised as remote attackers can create arbitrary commands e.g. using "wget" to download RCE files onto the system, create arbitrary Admins, delete users, and conduct DOS attacks.

Cross-Site Request Forgery vulnerability in Add From Server WordPress Plugin

It was discovered that Add From Server is vulnerabile to Cross-Site Request Forgery. It can be exploited by luring the target user into clicking a specially crafted link or visiting a malicious website (or advertisement). An attacker can use this issue to add illegal content to the victims server, or add very large files to the victim's server to exaust the amount of avalible disk space.

phpCollab v2.5 CMS – SQL Injection Vulnerability

A remote sql-injection web vulnerability has been discovered in the official phpCollab v2.5 content management system. The vulnerability allows remote attackers to execute own malicious sql commands to compromise the application or dbms. The sql-injection vulnerability is located in the `id` parameter of the `./phpcollab/users/` module GET method request. Remote attackers are able to execute own sql commands by usage of the insecure `emailusers.php` file GET method request.

Recent Exploits: