VARIoT IoT exploits database

VAR-E-201202-0723 | No CVE | OfficeSIP Server 3.1 Denial Of Service | No EDB ID |
OfficeSIP Server version 3.1 suffers from a remote denial of service vulnerability. Proof of concept exploit included.
VAR-E-201202-0193 |
CVE-2012-1008 |
OfficeSIP Server 3.1 - Denial of Service - Windows dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201202-0282 | EDB ID: 18453 |
OfficeSIP Server 3.1 - Denial of Service. CVE-78997CVE-2012-1008 . dos exploit for Windows platform
VAR-E-201201-0033 |
CVE-2013-0229 CVE-2013-0230 CVE-2012-5958 CVE-2012-5964 CVE-2012-5960 CVE-2012-5959 CVE-2012-5962 CVE-2012-5963 CVE-2012-5961 CVE-2012-5965 |
MiniUPnP 1.4 - Multiple Denial of Service Vulnerabilities - Multiple dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201301-0243 | EDB ID: 38249 |
MiniUPnP 1.4 - Multiple Denial of Service Vulnerabilities. CVE-2013-0229 . dos exploit for Multiple platform
VAR-E-201201-0656 |
CVE-2011-4039 CVE-2011-4038 |
Dream Report Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201202-0159, VAR-201202-0154 | No EDB ID |
Dream Report is prone to a cross-site scripting vulnerability and a remote code-execution vulnerability because the application fails to sufficiently sanitize user-supplied data.
Attackers can exploit these issues to execute arbitrary code in the context of the webserver, compromise the affected application, and steal cookie-based authentication credentials from legitimate users of the site. Other attacks are also possible.
These issues affect Dream Report Versions prior to 4.0.
VAR-E-201201-0658 |
CVE-2012-1807 CVE-2012-1808 CVE-2012-1805 CVE-2012-1806 CVE-2012-1809 |
Koyo ECOM100 Ethernet Module Multiple Security Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201204-0129, VAR-201204-0133, VAR-201204-0131, VAR-201204-0134, VAR-201204-0130 | No EDB ID |
Koyo ECOM100 Ethernet Module is prone to multiple unspecified vulnerabilities including:
1. A buffer-overflow vulnerability.
2. A denial-of-service vulnerability.
3. Multiple security-bypass vulnerabilities.
4. A cross site-scripting vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, bypass some security restrictions, allow an attacker to steal cookie-based information, or execute script code in the context of the browser of an unsuspecting user; other attacks may also be possible.
VAR-E-201201-0278 |
CVE-2012-0931 CVE-2012-0930 CVE-2012-0929 |
Schneider Electric Modicon Quantum Multiple Security Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201201-0146, VAR-201201-0148, VAR-201201-0147 | No EDB ID |
Schneider Electric Modicon Quantum is prone to multiple vulnerabilities including:
1. A remote code-execution vulnerability.
2. Multiple buffer-overflow vulnerabilities.
3. A security-bypass vulnerability.
4. A cross site-scripting vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, bypass some security restrictions, allow an attacker to steal cookie-based information, or execute script code in the context of the browser of an unsuspecting user; other attacks may also be possible.
VAR-E-201201-0167 |
CVE-2012-0221 CVE-2012-0222 |
Rockwell Automation FactoryTalk Activation Server - Multiple Denial of Service Vulnerabilities - Multiple dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201204-0173, VAR-201204-0174 | EDB ID: 36570 |
Rockwell Automation FactoryTalk Activation Server - Multiple Denial of Service Vulnerabilities. CVE-2012-0221CVE-78353 . dos exploit for Multiple platform
VAR-E-201201-0906 | No CVE | Pragyan CMS 'fileget' Parameter Remote File Disclosure Vulnerability | No EDB ID |
Pragyan CMS is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the webserver process, which may aid in further attacks.
Pragyan CMS 3.0 is vulnerable; other versions may also be affected.
VAR-E-201201-0557 |
CVE-2012-5293 |
SAPID 1.2.3 Stable - Remote File Inclusion - PHP webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201210-0426 | EDB ID: 18342 |
SAPID 1.2.3 Stable - Remote File Inclusion. CVE-82476CVE-82475CVE-2012-5293 . webapps exploit for PHP platform
VAR-E-201201-0283 |
CVE-2012-0902 |
AirTies-4450 - Unauthorized Remote Reboot (Denial of Service) - Hardware dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201201-0130 | EDB ID: 18336 |
AirTies-4450 - Unauthorized Remote Reboot (Denial of Service). CVE-78616CVE-2012-0902 . dos exploit for Hardware platform
VAR-E-201112-0004 |
CVE-2013-1775 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apple Mac OSX 10.8.4 - Local Privilege Escalation (Python) - OSX local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201303-0172 | EDB ID: 27965 |
Apple Mac OSX 10.8.4 - Local Privilege Escalation (Python). CVE-2013-1775CVE-90677 . local exploit for OSX platform
VAR-E-201110-0002 |
CVE-2012-0053 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apache - httpOnly Cookie Disclosure - Multiple remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201201-0038 | EDB ID: 18442 |
Apache - httpOnly Cookie Disclosure. CVE-2012-0053CVE-78556 . remote exploit for Multiple platform
VAR-E-201112-0008 |
CVE-2012-2336 CVE-2012-2311 CVE-2012-1823 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
PHP 5.3.12/5.4.2 - CGI Argument Injection (Metasploit) - PHP remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246 | EDB ID: 18834 |
PHP 5.3.12/5.4.2 - CGI Argument Injection (Metasploit). CVE-2012-2336CVE-81633CVE-2012-2311CVE-2012-1823 . remote exploit for PHP platform
VAR-E-201110-0004 |
CVE-2012-0031 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apache 2.2 - Scoreboard Invalid Free On Shutdown - Linux dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242 | EDB ID: 41768 |
Apache 2.2 - Scoreboard Invalid Free On Shutdown. CVE-2012-0031 . dos exploit for Linux platform
VAR-E-201112-0006 |
CVE-2012-2336 CVE-2012-2311 CVE-2012-1823 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
PHP < 5.3.12 / < 5.4.2 - CGI Argument Injection - PHP remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246 | EDB ID: 18836 |
PHP < 5.3.12 / < 5.4.2 - CGI Argument Injection. CVE-2012-2336CVE-2012-2311CVE-2012-1823CVE-81633 . remote exploit for PHP platform
VAR-E-201112-0003 |
CVE-2013-2465 CVE-2012-1823 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Oracle Java storeImageArray() Invalid Array Indexing
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305 | EDB ID: 40233 |
VAR-E-201112-0007 |
CVE-2012-2336 CVE-2012-2311 CVE-2012-1823 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner - PHP remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246 | EDB ID: 29316 |
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner. CVE-2012-2336CVE-2012-2311CVE-2012-1823CVE-81633 . remote exploit for PHP platform
VAR-E-201112-0002 |
CVE-2012-2336 CVE-2012-2311 CVE-2012-1823 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution - PHP remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201205-0305, VAR-201205-0312, VAR-201205-0246 | EDB ID: 29290 |
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution. CVE-2012-2336CVE-2012-2311CVE-2012-1823CVE-81633 . remote exploit for PHP platform
VAR-E-201112-0001 |
CVE-2013-1775 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apple Mac OSX - Sudo Password Bypass (Metasploit) - OSX local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201303-0172 | EDB ID: 27944 |
Apple Mac OSX - Sudo Password Bypass (Metasploit). CVE-2013-1775CVE-90677 . local exploit for OSX platform
VAR-E-201111-0001 |
CVE-2011-3639 CVE-2013-2465 CVE-2012-0507 CVE-2011-4885 CVE-2011-5035 |
Apache 2.2.15 mod_proxy - Reverse Proxy Security Bypass - Linux remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242 | EDB ID: 36663 |
Apache 2.2.15 mod_proxy - Reverse Proxy Security Bypass. CVE-2011-3639CVE-77444 . remote exploit for Linux platform