Exploits |
Description |
Additional Information |
Release Date |
|
Firebird CNCT Group Number Overflow
|
This module exploits a vulnerability in Firebird SQL Server. A
specially crafted packet can be sent which will overwrite a pointer allowing the attacker to control where data is read from. Shortly following the controlled read, the pointer is called resulting in code execution.
|
Blog: Coming soon!
|
3/07/2013
|
|
Surge FTP Command Injection
|
The SurgeFTP servers web-based administrative console is vulnerable to remote command injection. A specially crafted request can be sent to /cgi/surgeftpmgr.cgi to execute arbitrary commands within the context of the user running the application. An authenticated session is required to exploit this vulnerability.
Zip file MD5: 2319947afe302fdeb264cedc6c3d6369
|
Blog: Coming soon!
|
12/20/2012
|
|
MS11-080
|
This module exploits a flaw in the AfdJoinLeaf function of the
afd.sys driver to overwrite data in kernel space. An address within
the HalDispatchTable is overwritten and when triggered with a call
to NtQueryIntervalProfile will execute shellcode.
|
Blog: MS11-080 Revisited - Returning to Ring 0
|
9/26/2012
|
|
LifeSize Room
|
Multiple vulnerabilities within the LifeSize Room appliance.
Vulnerability Summaries: Login page can be bypassed, granting
administrative access to the web interface. Unauthenticated OS command
injection is possible through the web interface. The easiest way to
perform these attacks is using a web proxy. |
LifeSize Room Advisory |
8/29/2011 |
|
SiteScape TCL
Injection Sploit
|
Confirmation that SiteScape servers are vulnerable to TCL injection
allowing remote code execution through TCL payloads. SecureState has
released proof of concept exploit code for this vulnerability.
|
TCL
Advisory
TCL Whitepaper
TCL Blog |
1/10/2011 |