header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

CSRF vulnerability in Harris Stratex WIMAX 2100 subscriber station

A vulnerability was found in Harris Stratex WIMAX 2100 subscriber station, which allowed an attacker to view the current configuration of the subscriber station without authentication from both LAN & WAN. This was achieved by using a malicious HTML code which submitted a form to the target URL.

ArtForms 2.1b7.2 RC2 Joomla Component Multiple Remote Vulnerabilities

The parameters viewform and id are not properly sanitised before being used in a SQL query.This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The l parameter in alikon/captcha.php is not properly sanitised before being used to create a path for a file that will be downloaded.This can be exploited to download arbitrary files from local resources via directory traversal attacks. The afmsg parameter is not properly sanitised before being printed.This allows the execution of arbitrary HTML code.

SDMS(Simple document management system) SQli Vulnerability

A SQL injection vulnerability was discovered in the SDMS(Simple document management system) application. An attacker can exploit this vulnerability to execute arbitrary SQL commands in the application's back-end database. Demo URL: http://server/detail.php?doc_id=[sqli]

Sijio Community Software SQLi/Persistent XSS Vulnerability

The vulnerability is a SQL injection vulnerability in the 'parent' parameter of the 'gallery' page. An attacker can inject malicious SQL code into the parameter to gain access to the database. The vulnerability also includes a persistent XSS vulnerability in the blog section. An attacker can register and post malicious XSS code in the blog section, which will be executed when the main page is accessed.

HP NNM 7.53 ovwebsnmpsrv.exe Buffer Overflow (SEH)

This is the result of research on CVE-2010-1964. Finding this vulnerability locally was trivial but getting a remote exploit via jovgraph.exe never quite worked out. Overflowing many of the other command line options will overwrite SEH as well (e.g. -demo). The buffer contains an alphanumeric bind shell.

EvoCam Web Server OSX 3.6.6 and 3.6.7

A buffer overflow vulnerability exists in EvoCam Web Server OSX 3.6.6 and 3.6.7. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable server, which can lead to arbitrary code execution. The vulnerability is due to insufficient boundary checks when handling user-supplied input.

Joomla com_neorecruit BSqli Vulnerability

NeoRecruit is a recruitment component. It enables you to propose job and internship offers. The offers are classified in various categories and are allotted to a recruiter to which you can give access to the management of his offers from the website. NeoRecruit it is not simply a system which presents offers, it makes it possible to recover the CV and the covering letters of the applicants when apply to an offer. You thus create a true CV database, manageable from the backend or the frontend for recruiters.

Recent Exploits: