header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Recognize-Security – cPanel HTTP Response Splitting Vulnerability

An input validation problem exists within cPanel and WHM versions 11.25 (up to build 42174) which allows injecting CR (carriage return - %0D or
) and LF (line feed - %0A or
) characters into the server HTTP response header, resulting in a HTTP Response Splitting vulnerability. The vulnerability exists in the failurl parameter of cPanel login page. In a failed login attempt, the value of failurl returns to the client in the Location HTTP header. This vulnerability is possible because the application fails to validate user supplied input to failurl parameter, returning it un-sanitized within the server HTTP response header back to the client. This vulnerability not only gives attackers control of the remaining headers and body of the server response, but also allows them to create additional responses entirely under their control. Attacker-supplied HTML or JavaScript code could run in the context of the aflicted domain, allowing the attacker to steal cookie-based authentication credentials or to control the victim's browser in other malicious ways.

jetAudio 8.0.0.2 Basic (m3u) Stack Overflow Exploit

jetAudio 8.0.0.2 Basic (m3u) Stack Overflow Exploit is a buffer overflow vulnerability that allows an attacker to execute arbitrary code on the vulnerable system. The vulnerability is caused by a lack of boundary checks when processing a specially crafted m3u file. The exploit code creates a malicious m3u file containing a payload of 1017 A characters followed by a NSEH and SEH record, and a shellcode. The malicious m3u file is then sent to the vulnerable system, which causes the stack to overflow and the shellcode to be executed.

MP3 Studio v1.X (.m3u File) Local Stack Overflow Universal

This exploit is a local stack overflow vulnerability in MP3 Studio v1.X. It allows an attacker to execute arbitrary code by overflowing the buffer with 4103 'A' characters, followed by a short jump, a NOP sled, and shellcode. The exploit was tested on Windows XP SP2 and SP3.

AOL 9.5 ActiveX 0day Exploit (heap spray)

This exploit is a heap spray vulnerability in AOL 9.5 ActiveX. It was discovered by Hellcode Research and tested on Windows XP SP3 and IE7. The exploit uses a win32_exec shellcode to execute calc.exe. The exploit uses a heap spray technique to spray the heap with the shellcode and then uses the Import() method of the AOL 9.5 ActiveX control to trigger the vulnerability.

Pidgin MSN <= 2.6.4 file download vulnerability

Pidgin is a multi-protocol Instant Messenger. This is an exploit for the vulnerability discovered in Pidgin by Fabian Yamaguchi. The issue is caused by an error in the MSN custom smiley feature when processing emoticon requests, which could allow attackers to disclose the contents of arbitrary files via directory traversal attacks.

Microsoft Windows NT #GP Trap Handler Allows Users to Switch Kernel Stack

In order to support BIOS service routines in legacy 16bit applications, the Windows NT Kernel supports the concept of BIOS calls in the Virtual-8086 mode monitor code. These are implemented in two stages, the kernel transitions to the second stage when the #GP trap handler (nt!KiTrap0D) detects that the faulting cs:eip matches specific magic values. Transitioning to the second stage involves restoring execution context and call stack (which had been previously saved) from the faulting trap frame once authenticity has been verified. This verification relies on the following incorrect assumptions: Setting up a VDM context requires SeTcbPrivilege, ring3 code cannot install arbitrary code segment selectors, and ring3 code cannot forge a trap frame.

Recent Exploits: