This module exploits Hashicorp Consul's services API to gain remote command execution on Consul nodes.
This module exploits a feature of Hashicorp Consul named rexec.
This exploit allows an attacker to include remote files in the syndeoCMS 2.5.01 CMS directory.
This application has the vulnerability of uploading files with the extension 'php3' in the logo upload field. But the uploaded file must be in PNG format and size 150X40. We can put PHP code into image source. After you make the extension 'php3', the PHP code that we've placed can work. Therefore, PHP code can be executed using '<? ?>' Tags in PNG format file. I have exploited in 2 different ways. First one uploads a basic php shell for you and lets you control it through the console. Second one uploads the php meterpreter payload to the target site and lets you set this payload.
This exploit creates a file with a large payload, causing the ShareAlarmPro software to crash when attempting to open it. It is a proof-of-concept exploit that demonstrates the vulnerability in the software. The vulnerability allows an attacker to cause a denial of service condition by sending a specially crafted payload to the software.
This exploit allows an attacker to create a file that causes a denial of service in NetShareWatcher 1.5.8. By providing a specially crafted payload, the application crashes when the file is used in the registration process.
Unrestricted file upload for unahtorized user in package info upload process allowing arbitrary extension.
This vulnerability allows remote attackers to include arbitrary files via a URL in the site parameter of the index.php script.
This exploit takes advantage of a buffer overflow vulnerability in MAGIX Music Editor 3.1. By providing a specially crafted input, an attacker can overflow a buffer and overwrite the Structured Exception Handler (SEH) to gain control of the program flow. This allows the attacker to execute arbitrary code, such as launching a calculator application.
Allows it to run a Cross-Site Scripting by saving a new title from the console tab.