header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

sNews Cross-Site Scripting and HTML-Injection Vulnerabilities

sNews is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

Memory Corruption Vulnerability in Mozilla Firefox, Thunderbird, and Seamonkey

The vulnerability allows an attacker to execute arbitrary code in the context of the user running an affected application. It occurs due to inadequate validation of user-supplied data in Mozilla Firefox, Thunderbird, and Seamonkey.

PHP <= 4.4.6 ibase_connect() & ibase_pconnect() local buffer overflow

This is a proof-of-concept exploit for a local buffer overflow vulnerability in PHP versions <= 4.4.6. The vulnerability exists in the ibase_connect() and ibase_pconnect() functions. The exploit targets Windows 2000 SP3 EN and utilizes a SEH overwrite technique. The exploit was created by rgod.

HP Network Node Manager I PMD Buffer Overflow

This module exploits a stack buffer overflow in HP Network Node Manager I (NNMi). The vulnerability exists in the pmd service, due to the insecure usage of functions like strcpy and strcat while handling stack_option packets with user controlled data. In order to bypass ASLR this module uses a proto_tbl packet to leak an libov pointer from the stack and finally build the rop chain to avoid NX.

Pure-FTPd External Authentication Bash Environment Variable Code Injection

This module exploits the code injection flaw known as shellshock which leverages specially crafted environment variables in Bash. This exploit specifically targets Pure-FTPd when configured to use an external program for authentication.

Recent Exploits: