An SQL injection vulnerability exists in Joomla Component GBU FACEBOOK version 1.0.5 or lower. An attacker can send a specially crafted HTTP request to the vulnerable application in order to execute arbitrary SQL commands in the backend database. The vulnerable parameter is 'face_id' which is located in the URL http://127.0.0.1/index.php?option=com_gbufacebook&task=show_face&face_id=[INDONESIANCODER].
By sending a specially crafted UDP packet, an attacker can remotely obtain the following information: software and firmware versions, MAC, local and remote IP, model and PPPoE credentials in clear text.
The page '/AutoRestart.html' restores the default configuration and reboots the device. This page does not require authentication. From LAN or Client Side, just send a simple GET request to: http://192.168.1.254/AutoRestart.html. In case of having the remote interface enabled, from remote: http://<REMOTE IP>/AutoRestart.html. The page '/rpLocalDeviceJump.html' reboots the device when the 'index' variable value has a length of more than 7 characters. Requires authentication.
N/X WCMS 4.5 is prone to multiple vulnerabilities, including SQL-injection, cross-site scripting, and cross-site request-forgery vulnerabilities. An attacker can exploit these issues to manipulate SQL queries, steal cookie-based authentication credentials, control how the site is rendered to the user, and more.
AVTECH Software's AVC781Viewer ActiveX Control suffers from multiple remote vulnerabilities such as buffer overflow, integer overflow and denial of service (IE crash). This issue is triggered when an attacker convinces a victim user to visit a malicious website. Remote attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers. Failed exploit attempts likely result in browser crashes.
A vulnerability exists in Flex File Manager which allows an attacker to upload a malicious shell to the server. The attacker can then access the shell by navigating to the data directory of the application.
A Local File Inclusion (LFI) vulnerability exists in the com_if_surfalert version 1.2 component for Joomla. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing directory traversal characters (e.g. '../') to the vulnerable application. This can allow the attacker to include and execute arbitrary local files on the server.
A Local File Inclusion (LFI) vulnerability exists in the com_google version 1.2 component of Joomla. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This request contains a maliciously crafted parameter which can be used to include arbitrary files from the server. This can be used to gain access to sensitive information such as system files, configuration files, etc.
A Local File Inclusion (LFI) vulnerability exists in the com_drawroot version 1.1 component of Joomla. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This can allow the attacker to include a file from the local system and execute arbitrary code.
A local file inclusion vulnerability exists in com_multimap version 1.0, which is a component of Joomla. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing directory traversal sequences (e.g. '../') to the vulnerable server. This can allow the attacker to include and execute arbitrary local files on the vulnerable system.