header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

DVDXPlayer 5.5 Pro Local Buffer Overflow with SEH

This exploit takes advantage of a local buffer overflow vulnerability in DVDXPlayer 5.5 Pro. By sending a specially crafted payloadofficial.plf file, an attacker can trigger a buffer overflow and gain control of the SEH (Structured Exception Handling) chain. This allows the attacker to execute arbitrary code on the targeted system.

SerWeb <= 2.0.0 dev1 2007-02-20 Multiple RFI / LFI Vulnerabilities

Multiple Remote File Inclusion (RFI) and Local File Inclusion (LFI) vulnerabilities in SerWeb version 2.0.0 dev1 2007-02-20 allow attackers to include arbitrary files from remote servers or local file system, which could lead to remote code execution or unauthorized access to sensitive information.

WordPress Plugin PictPress <= release0.91 Remote File Disclosure Vulnerability

The vulnerability allows an attacker to disclose arbitrary files on the server by exploiting a file path traversal issue in the 'resize.php' script of the PictPress WordPress plugin. By manipulating the 'size' and 'path' parameters in the URL, an attacker can traverse directories and read sensitive files, such as the '/etc/passwd' file.

RDP Protocol Vulnerability

This exploit is used to perform a remote code execution attack on a target system that is vulnerable to the RDP protocol. The exploit takes advantage of a vulnerability in the RDP protocol implementation to execute arbitrary code on the target system. This can be used to gain unauthorized access to the target system or to launch further attacks.

Oracle Application Testing Suite WebLogic Server Administration Console War Deployment

This module abuses a feature in WebLogic Server's Administration Console to install a malicious Java application in order to gain remote code execution. Authentication is required, however by default, Oracle ships with a "oats" account that you could log in with, which grants you administrator access.

ezContents Version 1.4.5 Remote File Disclosure Vulnerability

This vulnerability allows an attacker to disclose arbitrary files on the server. By exploiting the '/ezcontents1_4x/index.php?link=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd' URL, an attacker can access sensitive files such as the '/etc/passwd' file.

SineCMS <= 2.3.4 Calendar SQL Injection 'n something else..

The SineCMS version 2.3.4 and below is vulnerable to SQL injection in the Calendar module. An attacker can exploit this vulnerability by sending a specially crafted request to the mods.php file, allowing them to retrieve sensitive information from the database. There are also other SQL injection vulnerabilities in the admin panel.

Recent Exploits: