header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

FCMS_2.2.3 Remote File Inclusion

The vulnerability exists due to insufficient sanitization of user-supplied input in the 'current_user_id' parameter in the 'familynews.php' and 'settings.php' scripts. This can be exploited to execute arbitrary PHP code by including a remote file via HTTP or FTP protocol.

CS CART 1.3.3 INSTALL.PHP XSS

If 'install.php' was not removed after installation, an attacker can create an HTML file with a form containing a text input and a submit button. The form action should be set to the path of the 'install.php' file on the victim server. After opening the HTML file, the attacker can enter any step of the installation they would like to access. Step '3' contains the most sensitive information.

Audiotran 1.4.2.4 SEH Overflow Exploit 0 day

This exploit is for Audiotran 1.4.2.4, a vulnerable application. The exploit is a buffer overflow vulnerability which is triggered when a maliciously crafted .pls file is loaded into the application. The exploit contains a NOP sled, shellcode and a POP POP RET sequence which is used to execute the shellcode. The exploit was tested on Windows XP SP2.

ES Simple Download v 1.0. Local File Exclusion/LFI

The vulnerability exists in ES Simple Download v 1.0. which allows an attacker to access sensitive files outside the web root directory by manipulating the 'file' parameter in the download.php script. The attacker can access the config.php file by sending a crafted request to the download.php script with the 'file' parameter set to '../../config.php'.

aradBlog Multiple Remote Vulnerabilities

In this latest of aradBlog you can access to Admin's dashboard with this virtual Path The value 'mainadmin' is a virtual path that defines in this DLL: App_Web_eqzheiif.dll and FastObjectFactory_app_web_eqzheiif class. You can upload any malicious file using this path: http://Example.com/mainadmin/downloads.aspx if you upload a shell.aspx for example,it will be in this path: shell.aspx ---> http://Example.com/downloads/uploads/2010_7_25_shell.aspx Note that : the value 2010_7_25 is the exact date of server.

FestOS CMS 2.3b Multiple Remote Vulnerabilities

This CMS has many critical vulnerabilities, including SQL Injection and Local File Inclusion (LFI). For SQL Injection, the proof of concept is to use the username and password 'admin' or '1'='1' in the admin.php page. For LFI, the proof of concept is to use the URL http://localhost/festos/index.php?theme=../admin/css/admin.css%00 in various pages such as artists.php, contacts.php, applications.php, entertainers.php, exhibitors.php, and foodvendors.php.

FreeBSD 8.1/7.3 vm.pmap kernel local race condition

Race condition in pmap, allows attackers to denial of service freebsd kernel. Creating a lot of process by fork() (~ kern.maxproc), it's possible to denial kernel. To bypass the MAXPROC from login.conf, attackers can use a few users to run PoC in this same time, to reach kern.maxproc.

Sirang Web-Based D-Control Multiple Remote Vulnerabilities

Vulnerability is located in content.asp line 131-133 and content.asp line 202-206. PoC: www.site.com/main_fa.asp?status=news&newsID=23'/**/union/**/all/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16/**/from/**/dc_admin/*. Bypass uploads restriction: js file line 13-34.

1024cms 2.1.1 Blind SQL Injection Vulnerability

A Blind SQL Injection vulnerability exists in 1024cms 2.1.1. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. This can allow the attacker to extract data from the database, including passwords and other sensitive information.

Integard Home/Pro version 2.0

This exploit is for Integard HTTP Server, vulnerability discovered by Lincoln. It allows an attacker to execute arbitrary code on the vulnerable system. The exploit is triggered when an attacker sends a specially crafted HTTP request to the vulnerable server.

Recent Exploits: