header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

GE Proficy HMI/SCADA CIMPLICITY 8.2 Local Privilege Escalation Exploit(0 day)

A vulnerability exists in GE Proficy HMI/SCADA CIMPLICITY 8.2 which allows an attacker to gain elevated privileges by exploiting the SERVICE_CHANGE_CONFIG privilege. The exploit code is written in C and uses the system() function to execute a malicious payload which changes the binary path of the CimProxy service to a malicious executable. The malicious executable is then executed with SYSTEM privileges.

OPAC KpwinSQL LFI/XSS Vulnerabilities

KpwinSQL suffers from an unauthenticated file inclusion vulnerability (LFI) when input passed thru the 'lang' parameter to the following scripts which are not properly verified: index.php, help.php, logpin.php, brow.php, indexs.php, search.php, hledani.php, hled_hesl.php before being used to include files. This can be exploited to include files from local resources with their absolute path and with directory traversal attacks. Moreover, KpwinSQL system suffers from Cross Site Scripting vulnerability when input passed thru the 'vyhl' parameter to 'index.php' script which does not perform input validation.

GNU Wget < 1.18 Arbitrary File Upload / Potential Remote Code Execution

GNU Wget before 1.18 when supplied with a malicious URL (to a malicious or compromised web server) can be tricked into saving an arbitrary remote file supplied by an attacker, with arbitrary contents and filename under the current directory and possibly other directories by writing to .wgetrc. Depending on the context in which wget is used, this can lead to remote code execution and even root privilege escalation if wget is run via a root cronjob as is often the case in many web application deployments. The vulnerability could also be exploited by well-positioned attackers within the network who are able to intercept/modify the network traffic.

AWBS v2.9.6 Multiple Remote Vulnerabilities

AWBS suffers from multiple SQL Injection vulnerabilities. Input passed via the 'cat' and 'so' GET parameters are not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Multiple cross-site scripting vulnerabilities were also discovered. The issue is triggered when input passed via multiple parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

SQL Injection In 24 Online Billing API

A non-privileged authenticated user can inject SQL commands on the <base-url>/24online/webpages/myaccount/usersessionsummary.jsp?invoiceid=<numeric-id> &fromdt=dd/mm/yyyy hh:mm:ss&todt= dd/mm/yyyy hh:mm:ss. There is complete informational disclosure over the stored database.

CIMA DocuClass Enterprise Content Management – Multiple Vulnerabilities

DocuClass is a modular and scalable enterprise content management (ECM) solution that allows organizations to streamline internal operations by significantly improving the way they manage their information within a business process. An unauthenticated attacker can read or modify data in the application database, execute code, and compromise the host system. An unauthenticated user can access stored documents by directly calling the document url. An unauthenticated attacker can execute malicious scripts in the user's browser.

eCardMAX 10.5 SQL Injection and XSS Vulnerabilities

eCardMAX suffers from a SQL Injection vulnerability. Input passed via the 'row_number' GET parameter is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Multiple cross-site scripting vulnerabilities were also discovered. The issue is triggered when input passed via multiple parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

WebCalendar v1.2.7 CSRF Protection Bypass

WebCalendar attempts to uses the HTTP Referer to check that requests are originating from same server. However, the application fails to check the Referer header when performing certain actions such as adding, deleting or modifying events. An attacker can craft a malicious link and send it to the victim, tricking them into performing actions without their knowledge.

Recent Exploits: