header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Dell OpenManage Server Administrator 8.2 Authenticated Directory Traversal

When authenticated as an admin, an attacker can manipulate the URL to access arbitrary files on the server. By substituting the target IP, desired file path, and session-specific vid parameter, the attacker can bypass security controls and view sensitive files.

bif3-0.4.1 <= Remote File Include Vulnerability

This vulnerability allows remote attackers to include arbitrary files via a crafted request to the Base/Application.php, Widgets/Base/Footer.php, Widgets/Base/widget.BifContainer.php, Widgets/Base/widget.BifRoot.php, Widgets/Base/widget.BifRoot2.php, Widgets/Base/widget.BifRoot3.php, or Widgets/Base/widget.BifWarning.php script.

JMX2 Email Tester – Web Shell Upload(save_email.php)

This exploit allows an attacker to upload a web shell using the 'save_email.php' file in the JMX2 Email Tester application. By providing a target URL and PHP code, the attacker can execute arbitrary commands on the target system.

Remote Command Execution in phpMyBackupPro v.2.5 (PMBP)

phpMyBackupPro v.2.5 (PMBP) allows a malicious user to inject persistent arbitrary PHP/OS commands into the configuration file, leading to remote command execution. This can be achieved through a CSRF driveby or by a local malicious user in a shared host environment. The payload leverages the backtick operator to execute OS commands on the victim's system.

Magic ISO Stacked Based Buffer Overflow

Magic iso has a stacked based buffer overflow vulnerability when an overly-long file name is passed inside the .cue file. This allows an attacker to control registers and execute commands. This exploit is currently released as a denial-of-service proof of concept until further help is received. Debug information shows that registers eax, ecx, and edx can be controlled.

Recent Exploits: