Exploitdb Exploits

2,689 exploits tracked across all sources.

Sort: Activity Stars
CVE-2013-0230 EXPLOITDB ruby VERIFIED
miniupnpd 1.0 - Remote Code Execution via Long Quoted Method in SOAPAction Handler
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
by Metasploit
CVE-2013-3563 EXPLOITDB ruby VERIFIED
Lianja SQL Server < 1.0 - Stack-Based Buffer Overflow via TCP Port 8001
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string to TCP port 8001.
by Metasploit
CVE-2012-5946 EXPLOITDB ruby VERIFIED
IBM SPSS SamplePower 3.0 - Buffer Overflow in c1sizer ActiveX Control via TabCaption
Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via a long TabCaption string.
by Metasploit
CVE-2013-2028 EXPLOITDB ruby VERIFIED
nginx 1.3.9-1.4.0 - Remote Code Execution via Chunked Transfer-Encoding
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
by Metasploit
CVE-2013-2730 EXPLOITDB ruby VERIFIED
Adobe Reader/Acrobat <9.5.5, <10.1.7, <11.0.03 - Buffer Overflow
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.
by Metasploit
CVE-2013-10059 EXPLOITDB HIGH ruby VERIFIED
D-Link DIR-615H1 <8.04 - Command Injection
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credentials, an attacker can exploit this blind injection vector to execute arbitrary commands.
by Metasploit
CVSS 7.2
CVE-2013-10058 EXPLOITDB HIGH ruby VERIFIED
Linksys router <v2.0.03 - Command Injection
An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution.
by Metasploit
CVE-2013-0136 EXPLOITDB ruby VERIFIED
Mutiny < 5.0-1.11 - Authenticated Path Traversal and Arbitrary File Write via EditDocument Servlet
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.
by Metasploit
CVE-2013-0726 EXPLOITDB ruby VERIFIED
ERDAS ER Viewer <13.00.0001 - Buffer Overflow
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code via a crafted pathname in an ERS file.
by Metasploit
EIP-2026-104071 EXPLOITDB ruby VERIFIED
SAP SOAP RFC - SXPG_COMMAND_EXECUTE Remote Command Execution (Metasploit)
by Metasploit
EIP-2026-104070 EXPLOITDB ruby VERIFIED
SAP SOAP RFC - SXPG_CALL_SYSTEM Remote Command Execution (Metasploit)
by Metasploit
CVE-2013-1347 EXPLOITDB HIGH ruby VERIFIED
Microsoft Internet Explorer 8 - Remote Code Execution via Use-After-Free
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
by Metasploit
CVSS 8.8
EIP-2026-116838 EXPLOITDB ruby VERIFIED
AudioCoder - '.m3u' Local Buffer Overflow (Metasploit)
by Metasploit
EIP-2026-116839 EXPLOITDB ruby VERIFIED
AudioCoder 0.8.18 - Local Buffer Overflow (SEH)
by metacom
CVE-2013-2010 EXPLOITDB CRITICAL ruby VERIFIED
W3 Total Cache < 0.9.2.8 - Remote PHP Code Execution
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
by Metasploit
CVSS 9.8
CVE-2013-3238 EXPLOITDB ruby VERIFIED
phpMyAdmin <3.5.8 and <4.0.0-rc3 - Authenticated RCE
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.
by Metasploit
EIP-2026-119106 EXPLOITDB ruby VERIFIED
SAP ConfigServlet - Remote Payload Execution (Metasploit)
by Andras Kabai
CVE-2013-3502 EXPLOITDB ruby VERIFIED
GroundWork Monitor Enterprise 6.7.0 - Authenticated Remote Code Execution via monarch_scan.cgi
monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by leveraging a JOSSO SSO cookie.
by Metasploit
CVE-2013-2423 EXPLOITDB LOW ruby VERIFIED
Oracle JRE - Improper Access Control
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.
by Metasploit
CVSS 3.7
CVE-2013-10060 EXPLOITDB HIGH ruby VERIFIED
Netgear router <1.0.0.36 - Command Injection
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the pppoe_username parameter. This flaw allows full compromise of the device and may persist across reboots unless configuration is restored.
by Metasploit
CVSS 7.2
EIP-2026-115837 EXPLOITDB ruby VERIFIED
Mikrotik Syslog Server for Windows 1.15 - Denial of Service (Metasploit)
by xis_one
EIP-2026-104069 EXPLOITDB ruby VERIFIED
SAP ConfigServlet - OS Command Execution (Metasploit)
by Andras Kabai
CVE-2013-1362 EXPLOITDB ruby VERIFIED
Opensuse < 2.13 - Improper Input Validation
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
by Metasploit
EIP-2026-101231 EXPLOITDB ruby VERIFIED
D-Link DIR-645 / DIR-815 - 'diagnostic.php' Command Execution (Metasploit)
by Metasploit
CVE-2013-0632 EXPLOITDB CRITICAL ruby VERIFIED
Adobe ColdFusion 9.0-9.0.2, 10 - Unauthenticated Authentication Bypass and Remote Code Execution via RDS Component
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
by Metasploit
CVSS 9.8