header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE

This module exploits a php object instantiation vulnerability in Shopware. An authenticated backend user could exploit the vulnerability. The vulnerability exists in the createInstanceFromNamedArguments function, where the code insufficiently performs whitelist check which can be bypassed to trigger an object injection. An attacker can leverage this to deserialize an arbitrary payload and write a webshell to the target system, resulting in remote code execution. Tested on Shopware git branches 5.6, 5.5, 5.4, 5.3.

Mambo/Joomla Component rsgallery <= 2.0 beta 5 (catid) Remote SQL Injection Vulnerability

Input passed to the "catid" parameter is not properly verified before being used to sql query. This can be exploited thru the browser and get the hash md5 password from users. Successful exploitation requires that "magic_quotes" is off.

Horde Webmail – XSS + CSRF to SQLi, RCE, Stealing Emails <= v5.2.22

Attacker can combine CSRF vulnerability in Trean Bookmarks and Stored XSS vulnerability in Horde TagCloud to steal victim's emails. Attacker can also use 3 different reflected XSS vulnerabilities to exploit Remote Command Execution, SQL Injection, and Code Execution. Attacker will send an email to the victim and when the victim clicks the attacker's website, the victim's inbox will be dumped in the attacker's FTP.

ReadCD local exploit

This exploit allows an attacker to escalate their privileges on a system using the ReadCD utility. It creates two C programs, s.c and ss.c, which are compiled and executed to gain root access. The exploit uses the setuid(0), setgid(0), chown, chmod, and execl functions to achieve this.

Recent Exploits: