Exploitdb Exploits

2,689 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-10013 EXPLOITDB CRITICAL ruby VERIFIED
AjaXplorer < 2.6 - Unauthenticated Remote Code Execution via access.ssh checkInstall.php destServer Parameter
An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters, remote attackers can execute arbitrary system commands on the server with the privileges of the web server process.
by Metasploit
EIP-2026-117522 EXPLOITDB ruby VERIFIED
Microsoft Windows - Escalate Service Permissions Privilege Escalation (Metasploit)
by Metasploit
EIP-2026-103982 EXPLOITDB ruby VERIFIED
Metasploit < 4.4 - pcap_log Plugin Privilege Escalation (Metasploit)
by 0a29406d9794e4f9b30b3c5d6702c708
CVE-2012-2516 EXPLOITDB ruby VERIFIED
GE Intelligent Platforms - Command Injection
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."
by Metasploit
CVE-2012-10039 EXPLOITDB CRITICAL ruby VERIFIED
ZEN Load Balancer <3.0-rc1 - Command Injection
ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in remote code execution as the root user. ZEN Load Balancer is the predecessor of ZEVENET and SKUDONET. The affected versions (2.0 and 3.0-rc1) are no longer supported. SKUDONET CE is the current community-maintained successor.
by Metasploit
CVE-2012-10038 EXPLOITDB CRITICAL ruby VERIFIED
Auxilium RateMyPet - Unauthenticated Arbitrary File Upload via Banner Upload Feature
Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a web-accessible /banners/ directory and can be executed directly, resulting in remote code execution.
by Metasploit
CVE-2012-10037 EXPLOITDB CRITICAL ruby VERIFIED
PhpTax 0.8 - Unauthenticated Remote Code Execution via drawimage.php pfilez Parameter
PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's context. No authentication is required.
by Metasploit
CVE-2012-0267 EXPLOITDB ruby VERIFIED
ntr_activex_control < 1.1.8 - Remote Code Execution via StopModule lModule Parameter
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer.
by Metasploit
CVE-2012-0266 EXPLOITDB ruby VERIFIED
NTR ActiveX Control < 2.0.4.8 - Remote Code Execution via Long bstrUrl or bstrParams
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method during construction of a .ntr pathname, or a long bstrUrl parameter to the (5) Download or (6) DownloadModule method during construction of a URL.
by Metasploit
CVE-2012-4969 EXPLOITDB HIGH ruby VERIFIED
Microsoft Internet Explorer <10 - RCE
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
by Metasploit
CVSS 8.1
CVE-2011-4051 EXPLOITDB ruby VERIFIED
InduSoft Web Studio 6.1 and 7.0 - Unauthenticated Remote Code Execution via CEServer Remote Agent
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.
by Metasploit
EIP-2026-118644 EXPLOITDB ruby VERIFIED
HP Application Lifecycle Management - 'XGO.ocx' ActiveX 'SetShapeNodeType()' Remote Code Execution (Metasploit)
by Metasploit
EIP-2026-118293 EXPLOITDB ruby VERIFIED
Avaya WinPMD UniteHostRouter - Remote Buffer Overflow (Metasploit)
by Metasploit
CVE-2012-3811 EXPLOITDB ruby VERIFIED
Avaya IP Office Customer Call Reporter 7.0-7.0.5.8 & 8.0-8.0.9.13 - RCE via Wallboard ImageUpload.ashx
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.
by Metasploit
EIP-2026-117524 EXPLOITDB ruby VERIFIED
Microsoft Windows - Escalate UAC Protection Bypass (Metasploit)
by Metasploit
EIP-2026-117523 EXPLOITDB ruby VERIFIED
Microsoft Windows - Escalate UAC Execute RunAs (Metasploit)
by Metasploit
CVE-2011-2005 EXPLOITDB HIGH ruby VERIFIED
Microsoft Windows XP/Server 2003 - Privilege Escalation
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
by Metasploit
CVSS 7.8
CVE-2012-2982 EXPLOITDB ruby VERIFIED
Webmin < 1.590 - Authenticated Remote Command Execution via Invalid Pathname Character
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
by Metasploit
EIP-2026-114802 EXPLOITDB ruby VERIFIED
QNX QCONN - Remote Command Execution (Metasploit)
by Metasploit
EIP-2026-111611 EXPLOITDB ruby VERIFIED
qdPM 7.0 - Arbitrary '.PHP' File Upload (Metasploit)
by Metasploit
CVE-2012-5159 EXPLOITDB ruby VERIFIED
phpMyAdmin 3.5.2.2 - Remote Code Execution via Trojaned server_sync.php
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.
by Metasploit
CVE-2012-1182 EXPLOITDB ruby VERIFIED
Samba < 3.4.16, 3.5.x < 3.5.14, 3.6.x < 3.6.4 - Remote Code Execution via RPC Array Length Validation Bypass
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.
by Metasploit
CVE-2009-1185 EXPLOITDB ruby VERIFIED
udev < 141 - Privilege Escalation via Unverified NETLINK Message
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
by Metasploit
EIP-2026-102347 EXPLOITDB ruby VERIFIED
Oracle Business Transaction Management FlashTunnelService - Remote Code Execution (Metasploit)
by Metasploit
CVE-2010-0188 EXPLOITDB HIGH ruby VERIFIED
Adobe Acrobat and Reader 8.x < 8.2.1 and 9.x < 9.3.1 - Remote Code Execution
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
by Metasploit
CVSS 7.8