VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201202-0723 No CVE OfficeSIP Server 3.1 Denial Of Service No EDB ID
OfficeSIP Server version 3.1 suffers from a remote denial of service vulnerability. Proof of concept exploit included.
VAR-E-201202-0193 CVE-2012-1008
OfficeSIP Server 3.1 - Denial of Service - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201202-0282
EDB ID: 18453
OfficeSIP Server 3.1 - Denial of Service. CVE-78997CVE-2012-1008 . dos exploit for Windows platform
VAR-E-201201-0033 CVE-2013-0229
CVE-2013-0230
CVE-2012-5958
CVE-2012-5964
CVE-2012-5960
CVE-2012-5959
CVE-2012-5962
CVE-2012-5963
CVE-2012-5961
CVE-2012-5965
MiniUPnP 1.4 - Multiple Denial of Service Vulnerabilities - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201301-0243
EDB ID: 38249
MiniUPnP 1.4 - Multiple Denial of Service Vulnerabilities. CVE-2013-0229 . dos exploit for Multiple platform
VAR-E-201201-0656 CVE-2011-4039
CVE-2011-4038
Dream Report Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201202-0159, VAR-201202-0154
No EDB ID
Dream Report is prone to a cross-site scripting vulnerability and a remote code-execution vulnerability because the application fails to sufficiently sanitize user-supplied data. Attackers can exploit these issues to execute arbitrary code in the context of the webserver, compromise the affected application, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible. These issues affect Dream Report Versions prior to 4.0.
VAR-E-201201-0658 CVE-2012-1807
CVE-2012-1808
CVE-2012-1805
CVE-2012-1806
CVE-2012-1809
Koyo ECOM100 Ethernet Module Multiple Security Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201204-0129, VAR-201204-0133, VAR-201204-0131, VAR-201204-0134, VAR-201204-0130
No EDB ID
Koyo ECOM100 Ethernet Module is prone to multiple unspecified vulnerabilities including: 1. A buffer-overflow vulnerability. 2. A denial-of-service vulnerability. 3. Multiple security-bypass vulnerabilities. 4. A cross site-scripting vulnerability. Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, bypass some security restrictions, allow an attacker to steal cookie-based information, or execute script code in the context of the browser of an unsuspecting user; other attacks may also be possible.
VAR-E-201201-0278 CVE-2012-0931
CVE-2012-0930
CVE-2012-0929
Schneider Electric Modicon Quantum Multiple Security Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201201-0146, VAR-201201-0148, VAR-201201-0147
No EDB ID
Schneider Electric Modicon Quantum is prone to multiple vulnerabilities including: 1. A remote code-execution vulnerability. 2. Multiple buffer-overflow vulnerabilities. 3. A security-bypass vulnerability. 4. A cross site-scripting vulnerability. Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, bypass some security restrictions, allow an attacker to steal cookie-based information, or execute script code in the context of the browser of an unsuspecting user; other attacks may also be possible.
VAR-E-201201-0167 CVE-2012-0221
CVE-2012-0222
Rockwell Automation FactoryTalk Activation Server - Multiple Denial of Service Vulnerabilities - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201204-0173, VAR-201204-0174
EDB ID: 36570
Rockwell Automation FactoryTalk Activation Server - Multiple Denial of Service Vulnerabilities. CVE-2012-0221CVE-78353 . dos exploit for Multiple platform
VAR-E-201201-0906 No CVE Pragyan CMS 'fileget' Parameter Remote File Disclosure Vulnerability No EDB ID
Pragyan CMS is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the webserver process, which may aid in further attacks. Pragyan CMS 3.0 is vulnerable; other versions may also be affected.
VAR-E-201201-0557 CVE-2012-5293
SAPID 1.2.3 Stable - Remote File Inclusion - PHP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201210-0426
EDB ID: 18342
SAPID 1.2.3 Stable - Remote File Inclusion. CVE-82476CVE-82475CVE-2012-5293 . webapps exploit for PHP platform
VAR-E-201201-0283 CVE-2012-0902
AirTies-4450 - Unauthorized Remote Reboot (Denial of Service) - Hardware dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201201-0130
EDB ID: 18336
AirTies-4450 - Unauthorized Remote Reboot (Denial of Service). CVE-78616CVE-2012-0902 . dos exploit for Hardware platform
VAR-E-201112-0004 CVE-2013-1775
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apple Mac OSX 10.8.4 - Local Privilege Escalation (Python) - OSX local Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201303-0172
EDB ID: 27965
Apple Mac OSX 10.8.4 - Local Privilege Escalation (Python). CVE-2013-1775CVE-90677 . local exploit for OSX platform
VAR-E-201110-0002 CVE-2012-0053
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apache - httpOnly Cookie Disclosure - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201201-0038
EDB ID: 18442
Apache - httpOnly Cookie Disclosure. CVE-2012-0053CVE-78556 . remote exploit for Multiple platform
VAR-E-201112-0008 CVE-2012-2336
CVE-2012-2311
CVE-2012-1823
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
PHP 5.3.12/5.4.2 - CGI Argument Injection (Metasploit) - PHP remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246
EDB ID: 18834
PHP 5.3.12/5.4.2 - CGI Argument Injection (Metasploit). CVE-2012-2336CVE-81633CVE-2012-2311CVE-2012-1823 . remote exploit for PHP platform
VAR-E-201110-0004 CVE-2012-0031
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apache 2.2 - Scoreboard Invalid Free On Shutdown - Linux dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242
EDB ID: 41768
Apache 2.2 - Scoreboard Invalid Free On Shutdown. CVE-2012-0031 . dos exploit for Linux platform
VAR-E-201112-0006 CVE-2012-2336
CVE-2012-2311
CVE-2012-1823
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
PHP < 5.3.12 / < 5.4.2 - CGI Argument Injection - PHP remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246
EDB ID: 18836
PHP < 5.3.12 / < 5.4.2 - CGI Argument Injection. CVE-2012-2336CVE-2012-2311CVE-2012-1823CVE-81633 . remote exploit for PHP platform
VAR-E-201112-0003 CVE-2013-2465
CVE-2012-1823
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Oracle Java storeImageArray() Invalid Array Indexing

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305
EDB ID: 40233
VAR-E-201112-0007 CVE-2012-2336
CVE-2012-2311
CVE-2012-1823
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner - PHP remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246
EDB ID: 29316
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner. CVE-2012-2336CVE-2012-2311CVE-2012-1823CVE-81633 . remote exploit for PHP platform
VAR-E-201112-0002 CVE-2012-2336
CVE-2012-2311
CVE-2012-1823
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution - PHP remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246
EDB ID: 29290
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution. CVE-2012-2336CVE-2012-2311CVE-2012-1823CVE-81633 . remote exploit for PHP platform
VAR-E-201112-0001 CVE-2013-1775
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apple Mac OSX - Sudo Password Bypass (Metasploit) - OSX local Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201303-0172
EDB ID: 27944
Apple Mac OSX - Sudo Password Bypass (Metasploit). CVE-2013-1775CVE-90677 . local exploit for OSX platform
VAR-E-201111-0001 CVE-2011-3639
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apache 2.2.15 mod_proxy - Reverse Proxy Security Bypass - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242
EDB ID: 36663
Apache 2.2.15 mod_proxy - Reverse Proxy Security Bypass. CVE-2011-3639CVE-77444 . remote exploit for Linux platform