Skybluecanvas version 1.1-r248 suffers from a cross site request forgery vulnerability.
5f2d732729618307cdfbe7efbc00f84fAcoustica Audio Converter Pro version 1.1 suffers from a heap overflow vulnerability.
5be5cb42b79b25e93aaba678eb290e95WebSuite suffers from a remote SQL injection vulnerability.
a688832f2068989f49ac3eaadd6eda98Atmail Webmail suffers from a cross site scripting vulnerability. Versions prior to 6.2.0 are affected.
6269664e25f288c80b1c27ac1706590fTuenti.com suffers from an insecure direct object reference vulnerability allowing anyone to read arbitrary blog posts.
85d8ff22e0e8fa88a47d5a589d279db8SnowFox Total Video Converter DLL hijacking exploit.
80c294ada1144897a6bb580ff188b66dSoftek Barcode Reader Toolkit version 7.1.4.14 Active-X related buffer overflow proof of concept exploit.
8aa99dc0ba8a0fc008402b9f2de625ccwpQuiz version 2.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
b95a0267ec3254d2181cca903235ce41ibPhotohost version 1.1.2 suffers from a remote SQL injection vulnerability.
e461d1dc666787bbdbe1c1912a630c3cMonth Of Abysssec Undisclosed Bugs - Microsoft Excel suffers from a WOPT record parsing heap memory corruption vulnerability. Proof of concept included.
312e375131ffd5c847ea5ffed7b32309Month Of Abysssec Undisclosed Bugs - Personal.Net Portal version 2.8.1 suffers from cross site request forgery and cross site scripting vulnerabilities.
5130c835c14bff57dbe9bae50467f6ddThis Metasploit module exploits a stack-based buffer overflow in Novell iPrint Client 5.42. When sending an overly long string to the 'call-back-url' parameter in an op-client-interface-version action of ienipp.ocx an attacker may be able to execute arbitrary code.
80269d9e5705e85962cc7e26d8957a01This Metasploit module exploits a stack-based buffer overflow in Novell iPrint Client 5.40. When sending an overly long string to the 'debug' parameter in ExecuteRequest() property of ienipp.ocx an attacker may be able to execute arbitrary code.
4c82e48d18c60cbb339bae8863c7b2e3This Metasploit module exploits the RPC service impersonation vulnerability detailed in Microsoft Bulletin MS10-061. By making a specific DCE RPC request to the StartDocPrinter procedure, an attacker can impersonate the Printer Spooler service to create a file. The working directory at the time is %SystemRoot%\\\\system32. An attacker can specify any file name, including directory traversal or full paths. By sending WritePrinter requests, an attacker can fully control the content of the created file. In order to gain code execution, this module writes an EXE and then (ab)uses the impersonation vulnerability a second time to create a secondary RPC connection to the \\\\PIPE\\\\ATSVC named pipe. We then proceed to create a remote AT job using a blind NetrJobAdd RPC call.
0580f4d44dd64fd3314f7ef5a0b654d1IB Promotion Advanced Business Web Suite suffers from a cross site scripting vulnerability.
0257fb75668e7c06518966721e1c6963BifrosT DLL hijacking exploit.
4da02dd48e7bdd3eaf62a990e2abf098Local proof of concept exploit that demonstrates a vulnerability with mountall where a udev rule is created with world-writable permissions.
ae2972ba5af4ed1176f2f3bacf6c2edaThe Joomla Spain component suffers from a remote SQL injection vulnerability.
193849dc55688bffac2043cf28828b7ce107 version 0.7.23 suffers from multiple remote SQL injection vulnerabilities.
73f05268f1c3c57fd1313bd5c7f0c32bSWiSHmax DLL hijacking exploit that leverages swishmaxres.dll.
659a7c7f61b374ae6d6145c80118d721Basic Web Server version 1.0 suffers from a directory traversal vulnerability.
e1a5f96dbc19da308d12b23dac842e6cBasic Web Server version 1.0 suffers from a denial of service vulnerability.
ae3d2a138a9cc23764217da57c8ae956SmarterMail version 7.1.3876 suffers from a directory traversal vulnerability.
198a340c0462c2c61592a8c59c2dfe5aPinky version 1.0 suffers from a directory traversal vulnerability.
dbe31b077aa6c02b1e5e1f245577f28cPrimitive CMS version 1.0.9 suffers from html and remote blind SQL injection vulnerabilities.
95341ffee52a8a6a78866eb18beead7f