A buffer overflow vulnerability exists in MP3 Workstation Version 9.2.1.1.2. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to a boundary error when handling specially crafted .pls files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to a boundary error when handling specially crafted .pls files.
Skybluecanvas.v1.1-r248 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to update the admin information without the knowledge of the admin. The attacker can craft a malicious HTML page with a form that contains the admin credentials and submit it to the vulnerable application. This will update the admin information without the knowledge of the admin.
This version of gausCMS have Multiple Valnerabilities: Access to Admin's Login and Information Disclosure and CSRF Upload arbitrary file and rename file. With this path you can easily access to Admin's Login: http://Example.com/admin_includes/template/languages/english/english.txt. With send a POST request to this path, you can upload arbitrary file of course by Admin's cookie and by CSRF technique.
wpQuiz version 2.7 is vulnerable to an authentication bypass vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. The request should contain an ID and PW parameter set to ' or '1=1. This will bypass the authentication and allow the attacker to access the application.
This vulnerability allows local attackers to gain elevated privileges on vulnerable installations of UDEV. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UDEV daemon. The issue lies in the fact that the daemon does not properly validate the source of events. An attacker can craft a malicious event and inject it into the UDEV daemon. This can be used to execute arbitrary code with elevated privileges.
This module exploits a stack-based buffer overflow in Novell iPrint Client 5.40. When sending an overly long string to the 'debug' parameter in ExecuteRequest() property of ienipp.ocx an attacker may be able to execute arbitrary code.
This module exploits a stack-based buffer overflow in Novell iPrint Client 5.42. When sending an overly long string to the 'call-back-url' parameter in an op-client-interface-version action of ienipp.ocx, an attacker may be able to execute arbitrary code.
The vulnerability is caused due to a boundary error in SoftekATL.DLL when handling the value assigned to the 'DebugTraceFile' property and can be exploited to cause a heap-based buffer overflow via an overly long string which may lead to execution of arbitrary code.
The ibPhotohost 1.1.2 application is vulnerable to a SQL injection vulnerability. This vulnerability is due to the application not properly sanitizing user-supplied input to the 'img' parameter of the 'index.php' script. An attacker can exploit this vulnerability by supplying a malicious SQL statement to the 'img' parameter. This can allow the attacker to view, add, modify, or delete data in the back-end database.
Acoustica Audio Converter Pro 1.1 (build 25) is vulnerable to a heap overflow vulnerability when a specially crafted .m3u file is opened. This can be exploited to execute arbitrary code by tricking a user into opening the malicious file.