header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Privilege Escalation in Panda Endpoint Administration Agent

Panda Endpoint Administration Agent v7.30.2 allows a local attacker to elevate his privileges from any account type (Guest included) and execute code as SYSTEM, thus completely compromising the affected host.

CVE-2016-3672 – Unlimiting the stack not longer disables ASLR

We have fixed an old and very known weakness in the Linux ASLR implementation. Any user able to running 32-bit applications in a x86 machine can disable the ASLR by setting the RLIMIT_STACK resource to unlimited. Following are the steps to test whether your system is vulnerable or not: Create a dummy program which shows its memory map, compile it, and run the application to check that ASLR is working. If the libc-2.19.so library is mapped at random positions, then ASLR is working properly. However, if the libc-2.19.so library is always mapped at the same position, then ASLR is not working.

SQL Injection in SocialEngine

The vulnerability exists due to insufficient filtration of input data passed via the "orderby" HTTP GET parameter to "/index.php" script. A remote unauthenticated attacker can modify present query and execute arbitrary SQL commands in application's database. A simple exploit below uses time-based SQL injection technique to demonstrate existence of the vulnerability.

Asbru Web Content Management System v9.2.7 Multiple Vulnerabilities

Asbru WCM suffers from multiple vulnerabilities including Cross-Site Request Forgery, Stored Cross-Site Scripting, Open Redirect and Information Disclosure.

Exploiting CVE-2014-4113

CVE-2014-4113 is a vulnerability in the Windows kernel that allows an attacker to gain SYSTEM privileges. The vulnerability exists in the way the Windows kernel handles objects in memory. An attacker can exploit this vulnerability by sending a specially crafted IOCTL request to a vulnerable driver. This will allow the attacker to gain SYSTEM privileges and execute arbitrary code in the kernel.

Use-after-free in SVG pattern element

A use-after-free vulnerability exists in the SVG pattern element in Microsoft Internet Explorer. An attacker can exploit this vulnerability by creating a malicious SVG file and convincing the user to open it. This will allow the attacker to execute arbitrary code on the target system.

Recent Exploits: