header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

[POC][Exploit] CodeCanyon Real3D FlipBook WordPress Plugin

This exploit is for the CodeCanyon Real3D FlipBook WordPress Plugin. It allows an attacker to delete Wordpress files by creating a malicious directory and uploading a malicious image. The attacker then uses the delete.php file to delete the Wordpress files.

Debian Exim Spool Local Root

Exim4 in some variants is started as root but switches to uid/gid Debian-exim/Debian-exim. But as Exim might need to store received messages in user mailboxes, it has to have the ability to regain privileges. This is also true when Exim is started as 'sendmail'. During internal operation, sendmail (Exim) will manipulate message spool files in directory structures owned by user 'Debian-exim' without caring about symlink attacks. Thus execution of code as user 'Debian-exim' can be used to gain root privileges by invoking 'sendmail' as user 'Debian-exim'.

Tiki CMS Unauthenticated File Upload Vulnerability

Tiki CMS is vulnerable to unauthenticated file upload. An attacker can upload a malicious file to the server without authentication. This vulnerability is due to the lack of authentication check in the 'connector.minimal.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious payload to the vulnerable script.

Ktools Photostore <= 4.7.5 Multiple Vulnerabilities

The Photostore application is prone to a multiple vulnerabilities such as SQL Injection & Cross Site Scripting and does not require any legitimate user or admin privilege to exploit them. A potentially attacker can exploit those vulnerabilities to retrieve all the data stored in the application's database (In case of SQL Injection vulnerability), Cookie Stealing / Phishing attacks (In case of Cross site scripting vulnerability). The vulnerability can be exploited by sending a maliciously crafted HTTP request to the application.

XpoLog Center V6 CSRF Remote Command Execution

XpoLog suffers from arbitrary command execution. Attackers can exploit this issue using the task tool feature and adding a command with respected arguments to given binary for execution. In combination with the CSRF an attacker can execute system commands with SYSTEM privileges.

Phoenix Exploit Kit – Remote Code Execution

The Phoenix Exploit Kit is vulnerable to a Remote Code Execution vulnerability due to the lack of proper input validation. An attacker can exploit this vulnerability by sending a crafted HTTP request with a malicious payload in the 'bdr' parameter to the vulnerable geoip.php file. This will allow the attacker to execute arbitrary code on the vulnerable system.

Ktools Photostore <= 4.7.5 (Pre-Authentication) Blind SQL Injection

The Photostore application password recovery module is prone to a blind sql injection attack. An attacker can exploit this vulnerability to retrieve all the data stored in the application's database.

Ubiquiti Administration Portal CSRF to Remote Command Execution

The Ubiquiti AirGateway, AirFiber and mFi platforms feature remote administration via an authenticated web-based portal. Lack of CSRF protection in the Remote Administration Portal, and unsafe passing of user input to operating system commands exectuted with root privileges, can be abused in a way that enables remote command execution.

Symantec SEPM Multiple Vulnerabilities

The management console for SEPM contains a number of security vulnerabilities that could be used by a lower-privileged user or by an unauthorized user to elevate privilege or gain access to unauthorized information on the management server. Exploitation attempts of these vulnerabilities requires access to the SEP Management console. XSS can bypass the 'http-only' cookie protection because the SEPM application writes and stores the session ID within various javascript functions used by the application within the DOM thereby exposing them directly to the XSS attack.

Lenovo ThinkPad System Management Mode arbitrary code execution exploit

This code exploits a 0day privilege escalation vulnerability (or backdoor?) in SystemSmmRuntimeRt UEFI driver (GUID is 7C79AC8C-5E6C-4E3D-BA6F-C260EE7C172E) of Lenovo firmware. Running of arbitrary System Management Mode code allows attacker to disable flash write protection and infect platform firmware, disable Secure Boot, bypass Virtual Secure Mode (Credential Guard, etc.) on Windows 10 Enterprise and do others evil things.

Recent Exploits: