An attacker can exploit a SQL injection vulnerability in the 'forgot-password.php' page of the Online Shopping Portal 3.1 application. The 'email' parameter is not properly sanitized, allowing an attacker to inject malicious SQL code into the query. This can be used to change the password of any user in the application.
Sickbeard 0.1 is vulnerable to Remote Command Injection. An attacker can exploit this vulnerability by setting malicious commands in the 'Extra Scripts' field of the Sickbeard configuration page. The malicious commands can be executed when a local video is processed. This vulnerability affects Sickbeard version alpha (master) -- git : 31ceaf1b5cab1884a280fe3f4609bdc3b1fb3121 running on Fedora 32.
This exploit is for FreeBSD 12.0-RELEASE x64 Kernel. It is used to exploit a vulnerability in the kernel of the operating system. The exploit uses clang to compile the exploit.c file and then runs it. It includes various header files such as errno.h, fcntl.h, stdio.h, string.h, stddef.h, stdlib.h, unistd.h, pthread.h, sys/event.h, sys/file.h, sys/filedesc.h, sys/param.h, sys/proc.h, sys/socket.h, sys/socketvar.h, netinet/in.h, netinet/in_pcb.h, netinet/ip6.h, netinet6/ip6_var.h, etc. It also defines various constants such as ELF_MAGIC, IPV6_2292PKTINFO, IPV6_2292PKTOPTIONS, TCLASS_MASTER, TCLASS_SPRAY, TCLASS_TAINT, NUM_SPRAY_RACE, NUM_SPRAY, NUM_KQUEUES, ALLPROC_OFFSET, PKTOPTS_PKTINFO_OFFSET, PKTOPTS_RTHDR_OFFSET, PKTOPTS_TCLASS_OFFSET, PROC_LIST_OFFSET, PROC_UCRED_OFFSET, PROC_FD_OFFSET, PROC_PID_OFFSET, FILEDESC_FILES_OFFSET, FILEDESCENTTBL_OFILES_OFFSET, FILEDESCENTTBL_NFILES_OFFSET, FILEDESCENT_FILE_OFFSET, FILE_TYPE_OFFSET, FILE_DATA_OFFSET, SOCKET_PCB_OFFSET, INPCB_IN6PCB_OFFSET, IN6PCB_PKTOPTS_OFFSET, etc. It is used to exploit a vulnerability in the kernel of the operating system.
This exploit allows an attacker to execute arbitrary code on the F5 Big-IP system and read files from the system. The exploit is achieved by sending a maliciously crafted HTTP request to the F5 Big-IP system, which contains a command to execute arbitrary code or a file read command.
This exploit allows an attacker to execute arbitrary code on a vulnerable F5 BIG-IP system. It requires Java JDK, hsqldb.jar 1.8, and ysoserial https://jitpack.io/com/github/frohoff/ysoserial/master-SNAPSHOT/ysoserial-master-SNAPSHOT.jar. The exploit uses the ysoserial tool to generate a malicious payload, which is then sent to the vulnerable system. The payload is then executed on the system, allowing the attacker to gain remote code execution.
An authenticated remote code execution vulnerability exists in Nagios XI 5.6.12. An attacker can exploit this vulnerability by sending a specially crafted request to the export-rrd.php script. This will allow the attacker to execute arbitrary code on the vulnerable system.
Authenticated users can bypass authorization and get full access to Workpoint Architect module. This module gives possibility to run Groovy scripts which results in Code Execution. First user needs to learn username and password for Architect (different from Aveksa login). Then log into Architect and create a new script that bypasses Java Security Policy and runs 'id' system command. Finally, execute the script.
This exploit sends an evil http request to the target with a payload of 1015 'A' characters, causing the Fire Web Server 0.1 to crash.
A persistent cross-site scripting vulnerability exists in File Management System 1.1. An attacker can inject malicious JavaScript code into the 'name' parameter of the 'view_admin.php' page, which will be executed when the page is viewed. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
An authentication bypass vulnerability exists in Online Shopping Portal 3.1. An attacker can bypass authentication by using SQL injection with '# or ' OR 1=1# as username and any password. After bypassing authentication, an attacker can upload a shell to the remote code execution. The shell can be found in the productimages folder and can be used to execute code.