header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

DeviceViewer 3.12.0.1 – ‘creating user’ DOS buffer overflow

DeviceViewer 3.12.0.1 is vulnerable to a buffer overflow attack when creating a new user. An attacker can generate a malicious payload via the POC and set the username to the malicious payload when creating a new user. This will cause the program to crash.

Authenticated Local File Inclusion(LFI) in GilaCMS

Authenticated Local File Inclusion(LFI) vulnerability exists in GilaCMS version 1.10.9. An attacker can exploit this vulnerability by sending a crafted request to the application. An attacker can include a local file on the server by sending a crafted request to the application. This can lead to sensitive information disclosure.

Western Digital My Book World II NAS <= 1.02.12 - Broken Authentication to RCE

The default password for SSH is 'welc0me' and the only security measure preventing SSH Login is the disabled SSH Port and it can be enabled with above POST Header. The attacker can then login to SSH Port with default password. WD My Book World II NAS is very outdated hardware and Western Digitial may never release update for it. It is still using PHP 4 so it has more potential of Remote Exploits. All firmwares listed at https://support.wdc.com/downloads.aspx?p=130&lang=en are vulnerable.

Recent Exploits: