header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Exotic-Cams –LFI & XSS–

Malicious users may upload shell's in order to gather control from the site. Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An attacker can steal the session cookie and take over the account.

Local File Inclusion and Remote File Inclusion Vulnerability in Profbiz-Cart

The Profbiz-Cart application is vulnerable to Local File Inclusion (LFI) and Remote File Inclusion (RFI) attacks. The vulnerable code is present in the dl-authcontent.php, dl-maincatsearch-dlcontent.php and dloads-payed.php files. An attacker can exploit this vulnerability by sending a crafted HTTP request containing malicious code in the docroot parameter. This will allow the attacker to read sensitive files from the server or execute arbitrary code on the server.

ActiveX – Denial of Service

Vulnerability is in Activex Control(msgsc.14.0.8089.726.dll) Sending a string to ViewProfile() , cause a crash on msnmsgr.exe *must be signed in Msn Messenger account for triggerin the vulnerability.

This exploit is a buffer overflow vulnerability in the TestObj ActiveX control. The vulnerability is caused by a lack of bounds checking when handling user-supplied data. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable ActiveX control. This can allow the attacker to execute arbitrary code on the target system.

Cms Site 1.0 (print_view) Blind SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable application. This can be done by manipulating the 'print_view' parameter of the vulnerable application. The attacker can use this vulnerability to gain access to the database and execute arbitrary SQL commands.

SopCast SopCore Control ActiveX Remote Exec 0day poc

This exploit is a proof-of-concept for a remote code execution vulnerability in the SopCast SopCore Control ActiveX control. The vulnerability exists due to an unsafe call to the CreateObject() method, which allows an attacker to execute arbitrary code on the vulnerable system. The exploit is available as a zip file containing a proof-of-concept exploit code.

Recent Exploits: