October 19, 2022Zimbra Privilege Escalation

This Metasploit module exploits a vulnerable sudo configuration that permits the Zimbra user to execute postfix as root. In turn, postfix can execute arbitrary shellscripts, which means it can execute a root shell.

October 19, 2022AVS Audio Converter 10.3 Stack Overflow

AVS Audio Converter version 10.3 suffers from a stack overflow vulnerability.

October 17, 2022Webile 1.0.1 Directory Traversal

Webile version 1.0.1 suffers from a directory traversal vulnerability.

October 17, 2022MiniDVBLinux 5.4 Unauthenticated Stream Disclosure

MiniDVBLinux versions 5.4 and below suffer from an unauthenticated live stream disclosure when /tpl/tv_action.sh is called and generates a snapshot in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).

October 17, 2022Backdoor.Win32.DarkSky.23 MVID-2022-0648 Buffer Overflow

Backdoor.Win32.DarkSky.23 malware suffers from a buffer overflow vulnerability.

October 17, 2022MiniDVBLinux 5.4 Change Root Password

MiniDVBLinux versions 5.4 and below root password changing proof of concept exploit.

October 17, 2022MiniDVBLinux 5.4 SVDRP Control

MiniDVBLinux versions 5.4 and below allows the usage of the SVDRP protocol/commands to be sent by a remote attacker to manipulate and/or remotely control the TV.

October 17, 2022MiniDVBLinux 5.4 Configuration Download

MiniDVBLinux versions 5.4 and below are vulnerable to an unauthenticated configuration download when a direct object reference is made to the backup function using an HTTP GET request.

October 17, 2022Joomla Vik Appointments 1.7.3 Cross Site Scripting

Joomla Vik Appointments extension version 1.7.3 suffers from a cross site scripting vulnerability.

October 17, 2022MapTool 1.11.5 Cross Site Scripting

MapTool version 1.11.5 suffers from a cross site scripting vulnerability.

Archives
Categories
  • All Exploits 4095
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow