Exploit Database
153,556 exploits tracked across all sources.
Accellion File Transfer Appliance < 9_12_40 - Cross-Site Scripting via OAuth Playground Callback URI
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
CVSS 6.1
Accellion FTA <FTA_9_12_180 - Info Disclosure
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
CVSS 6.1
Accellion File Transfer Appliance < 9_12_40 - SQL Injection via report_error.php Year Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
CVSS 9.8
Accellion File Transfer Appliance < 9_12_40 - LDAP Injection via ldaptest.html Filter Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
CVSS 9.8
Accellion FTA <FTA_9_12_180 - Auth Bypass
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.
CVSS 6.1
Accellion File Transfer Appliance < 9_12_40 - Cross-Site Scripting via User Add Param Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
CVSS 6.1
Accellion File Transfer Appliance < 9_12_40 - Same Origin Policy Bypass via acallow Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.
CVSS 8.8
Accellion File Transfer Appliance < 9_12_40 - Server-Side Request Forgery via URL Validation Bypass
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
CVSS 10.0
Accellion File Transfer Appliance < 9_12_40 - Cross-Site Scripting via SMTG Add Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
CVSS 6.1
Accellion File Transfer Appliance < 9_12_40 - SQL Injection via app_id Parameter
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
CVSS 9.8
TerraMaster Operating System < 3.0.33 - Remote Code Execution via GetTest.php Shell Metacharacter Injection
Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.
CVSS 9.8
Cognito Software Moneyworks <8.0.3 - Info Disclosure
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.
CVSS 9.8
zzcms < 8.3 - SQL Injection in zt/top.php
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.
CVSS 9.8
WpDevArt Booking calendar <2.2.2 - Info Disclosure
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
CVSS 7.5
D-Link DIR-601 A1 1.02NA - Info Disclosure
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
CVSS 8.1
MyBB 1.8.15 - Open Redirect via Target Attribute Handling
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
CVSS 6.1
Directus 6.4.9 - Use of Hard-coded Credentials
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
CVSS 9.8
diqee360_firmware - Authenticated Remote Code Execution via UDP Command 153
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute commands on the vacuum cleaner as root. The bug is in the function REQUEST_SET_WIFIPASSWD (UDP command 153). A crafted UDP packet runs "/mnt/skyeye/mode_switch.sh %s" with an attacker controlling the %s variable. In some cases, authentication can be achieved with the default password of 888888 for the admin account.
CVSS 7.5
Diqee Diqee360 Firmware - Unauthenticated Remote Code Execution via Unsigned Firmware Update Script
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital signature, as root from the /mnt/sdcard/$PRO_NAME/upgrade.sh or /sdcard/upgrage_360/upgrade.sh pathname.
CVSS 7.8
EtereWeb < 28.1.20 - Unauthenticated Blind SQL Injection via txUserName and txPassword Parameters
Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.
CVSS 9.8
SoftCase T-Router Firmware - Unauthenticated Remote Code Execution via T-Router Protocol
An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in production builds as of Spring 2018.
CVSS 9.8
SoftCase T-Router Firmware - Unauthenticated Arbitrary File Read and Write
An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary files on the system as root, as demonstrated by code execution after writing to a crontab file. This is fixed in production builds as of Spring 2018.
CVSS 9.8
Sonus SBC 1000/2000/SWe Lite - Unauthenticated Privilege Escalation
A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
CVSS 9.8
Sonus SBC 1000/2000/SWe Lite - Remote Code Execution
A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary commands via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
CVSS 9.8
Sonus SBC 1000/2000/SWe Lite - Local File Inclusion via Web Interface
A Local File Inclusion (LFI) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the downloading of arbitrary files via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
CVSS 7.5
By Source