header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Authenticated Remote File Disclosure

This vulnerability allows an attacker to bypass authentication and access sensitive files on NETGEAR ADSL routers. The vulnerability exists in the webproc CGI script, which allows an attacker to access the /etc/shadow file without authentication. This can be exploited by sending a specially crafted HTTP request to the vulnerable router.

Memcached SASL Authentication Bypass Vulnerability

This exploit is related to the CVE-2018-1000115 vulnerability in Memcached. This vulnerability allows an attacker to bypass the authentication process of Memcached and gain access to the server. The exploit is written in Python and uses a socket connection to send a specially crafted packet to the server. The packet contains a MEMCACHED_REQUEST_MAGIC, OPCODE_SET, key_len, body_len, and a payload of 1000 bytes. Upon receiving the packet, the server will respond with a confirmation message.

InfraPower PPS-02-S Q213V1 Authentication Bypass Vulnerability

The device does not properly perform authentication, allowing it to be bypassed through cookie manipulation. The vulnerable function checkLogin() in 'Function.php' checks only if the 'Login' Cookie is empty or not, allowing easy bypass of the user security mechanisms.

Boonex Dolphin all versoin <= 7.3 Authentication Bypass

According to PHP documentation strcmp will compare strings, but what if we provide an array??? So, simple bypass is to put two cookies in browser memberID=1 memberPassword[]=blah --->array This will allow the attacker to bypass the authentication and can also enter in admin panel.

WIMAX MT711x – Multiple Vulnerabilities

I'm an ethical penetration tester and super moderator of Iran Security Team. I have updated the modem to latest firmware which released by the company. but with this work(upgrading the firmware); The attacker can bypass the authentication mechanism. I used BurpSuite, wget and Nmap to find the vulnerabilities. The attacker can get the WIFI settings, Wimax credentials, enable and disable connections to modem, launch (D)DOS attack and change the password of ADMIN account.

Kirby CMS <= 2.1.0 Authentication Bypass via Path Traversal

KirbyCMS has a vulnerability that allows to bypass authentication in a hosting environment where users within the same shared environment can save/read files in a directory accessible by both the victim and the attacker. During the process, it fails to validate the resulting path to ensure that it does not contain path traversal sequences such as '../' within the login variable provided by a user.

Recent Exploits: