This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of software utilizing EMC AlphaStor. A remote user can send specially crafted data to TCP port 41025 to trigger a stack overflow and execute arbitrary code on the target system.
This module exploits a remote PHP code injection vulnerability in Elastix PBX by uploading a renamed PHP file and leveraging a local file inclusion vulnerability to execute the PHP file. It also exploits a bad configuration in the /etc/sudoers file to elevate privileges from 'asterisk' user to 'root'.
An internal memory buffer may be overrun while handling long "APPE" command. This condition may be exploited by attackers to ultimately execute instructions with the privileges of the ftpbasicsvr.exe process. Easy FTP server will be left inaccessible after successful exploitation.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of software utilizing Easy File Sharing Web Server. The vulnerability is caused due to a boundary error within Easy File Sharing Web Server when processing HTTP GET Request. This can be exploited to cause a stack-based buffer overflow via an overly long, specially-crafted argument passed to the affected command. Authentication is not required to exploit this vulnerability.