LanSpy.exe is prone to a buffer overflow vulnerability. This vulnerability occurs when a malicious 'addresses.txt' file is loaded by the application. The payload for the buffer overflow must be the very first entry in the text file. When the application is run and the scanning process is initiated, the program crashes, allowing an attacker to control the EIP at 684 bytes and overwrite both the NSEH & SEH exception handler pointers.
The exploit allows an attacker to perform a remote SQL injection attack on the PHP Coupon Script 3.0. By manipulating the 'bus' parameter in the 'index.php?page=viewbus' page, the attacker can inject SQL code to retrieve sensitive information from the database, such as usernames and passwords.
The fastreader application fails to sanitize user-supplied input, allowing an attacker to execute arbitrary commands in the context of the affected application.
Multiple CSRF vectors exist within FTGate v7 allowing various attacks like adding arbitrary domains, enabling arbitrary remote archiving of logs, whitelisting arbitrary email addresses, adding arbitrary mailbox & disabling antivirus, and removing email attachment blocking for files.
The vulnerability allows an attacker to include a remote file in the header.php file of the Open Translation Engine (OTE) version 0.7.8. By exploiting this vulnerability, an attacker can execute arbitrary code on the target system.
Multiple CSRF vectors exist within FTGate 2009 that allow us to add arbitrary remote domains, disable antivirus scanning for various Email file attachment types, and finally change settings to have archived server logs sent to our remote attacker controlled server for safe keeping.
Remote file inclusion vulnerabilities have been discovered in phpChess Community Edition 2.0. The vulnerabilities can be exploited by an attacker by including a malicious file through the 'Root_Path' parameter in certain PHP files.
The '/title' argument when supplied an overly long payload will overwrite NSEH & SEH exception handlers causing buffer overflow, allowing the execution of arbitrary shellcode. This vulnerability can be exploited by replacing a local .bat file with a malicious one.
The WordViewer.ocx version 3.2.0.5 is vulnerable to Denial of Service attacks through multiple methods. The affected methods include DoOleCommand, FTPDownloadFile, FTPUploadFile, HttpUploadFile, GotoPage, Save, and SaveWebFile.
The vulnerability allows an attacker to perform SQL injection by manipulating the 'id' parameter in the 'index.php?module=v4bJournal&func=journal_comment' URL. By using a specially crafted payload, an attacker can retrieve sensitive information from the 'nuke_users' table.