header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Microsoft Event Viewer XXE File Exfiltration

Windows Event Viewer user can import 'Custom View' files, these files contain XML, the parser processes External Entity potentially allowing attackers to gain remote file access to files on a victims system if user imports a corrupt XML file via remote share/USB (or other untrusted source).

Musoo 0.21(GLOBALS[ini_array][EXTLIB_PATH]) Remote File Include

The Musoo 0.21 version is vulnerable to remote file inclusion. The vulnerability exists in the 'msDb.php', 'MusooTemplateLite.php', and 'SoundImporter.php' files. An attacker can exploit this vulnerability by manipulating the 'GLOBALS[ini_array][EXTLIB_PATH]' parameter in the URL to include a malicious file. Three exploits are provided in the text, each targeting a different file.

Dirty COW Local Privilege Escalation

The Dirty COW (Copy-On-Write) vulnerability allows local attackers to gain root privileges on Linux systems. It exploits a race condition in the copy-on-write mechanism of the kernel's memory subsystem. By modifying certain system files, an attacker can gain root access and execute arbitrary code.

Type Confusion Vulnerability in Microsoft Internet Explorer

A specially crafted web-page can cause a type confusion vulnerability in Microsoft Internet Explorer 8 through to 11. An attacker can cause code to be executed with a stack layout it does not expect, or have code attempt to execute a method of an object using a vftable, when that object does not have a vftable. Successful exploitation can lead to arbitrary code execution.

Recent Exploits: