This archive contains all of the 162 exploits added to Packet Storm in April, 2014.
5007010267078b63a4b3b6a4243ee9a14e54335fe86b574a638aafce29bff230
BarracudaDrive version 6.7.1 suffers from multiple persistent and reflective cross site scripting vulnerabilities.
0a2ef5f75a8530b4c12f4d929e7c3fa5ef16f61b8b0b3a34dbfee192690742b5
Lavarel-Security cross site scripting filter suffers from a bypass vulnerability.
74a3d9484d7c2708d5444ae78215745101425b380c8a4b50a833eee46fd07a68
This Metasploit module exploits a type confusion vulnerability found in the ActiveX component of Adobe Flash Player. This vulnerability was found exploited in the wild in November 2013. This Metasploit module has been tested successfully on IE 6 to IE 10 with Flash 11.7, 11.8 and 11.9 prior to 11.9.900.170 over Windows XP SP3 and Windows 7 SP1.
2547432fd02f1ba4aff29ae93a0c14c41a56c95f4cec7e25e1165d0846aa03ec
NULL NUKE CMS version 2.2 suffers from cross site request forgery, cross site scripting, arbitrary file deletion, remote command execution, arbitrary file access, directory traversal, open redirection, and remote shell upload vulnerabilities.
885c0aa9f9866fb98106773eb936825f19e7e0540b5ae94b279a5b78a8858214
TRENDnet TEW-634GRU version 1.00.23 suffers from local file disclosure, router crash, and privilege escalation vulnerabilities.
38342dcf82a4e158add2c032f5e76a186438778accbb57fe5bb4c316489090c3
NTP ntpd monlist query reflection denial of service exploit.
fc458431c984a824aac0863ef7422ed300c3dc830b42f819b52b5db6f76ba518
McAfee ePolicy Owner (ePowner) version 0.1 is an exploit that can add an administrative user to McAfee ePolicy Orchestrator as well as execute arbitrary commands on versions 4.6.0 through 4.6.5.
0d651b0edd706e44bde243c2797b7f496490b9316136b12f61d3d2aa3d0e1523
Symantec Endpoint Protection Manager version 12.1.2015.2015 SEH overflow proof of concept exploit.
8bee128e1781c61bead3c3b0efa4f85a7a42194ff51d0beaf8d2d0e973d01216
Cells Blog version 3.4 suffers from a cross site scripting vulnerability.
ac38eaafb762b8cd9ec3b83028d2896357b2d5a6ff887d5e608437f19de3ff8e
CalendarScript version 3.2.1 suffers from a remote password disclosure vulnerability. Note that this finding houses site-specific data.
2e13799d7288e78b76f6fa3dbafdf7e565429515f7fc0f98fd86950948824f2d
Adem version 0.5.1 suffers from a local file inclusion vulnerability.
5490331b8db5b36ceac02b07263b7087277af584b62dbd78bccb2cfc1a49abbc
Kmplayer versions 3.8.0.122 and 3.8.0.123 suffer from a dll hijacking vulnerability.
4f4e9badb8f84d790e98982d772cc340148cbc9c1495f5667c8e623b4e81ca66
Tapatalk Forum suffers from a cross site scripting vulnerability.
253cd5c79575f7fb9259f5fda766b097a52ff591c1badea81b43b1012790918a
This Metasploit module triggers a stack buffer overflow in Wireshark versions 1.8.12/1.10.5 and below by generating an malicious file.
9a0517e6d1e5163de35e4817296671008162392223a5c12c8ee4a7970047e1f9
This exploit leverage a stack overflow vulnerability to escalate privileges. The vulnerable function nfs_convert_old_nfs_args does not verify the size of a user-provided argument before copying it to the stack. As a result by passing a large size, a local user can overwrite the stack with arbitrary content. Mac OS X Lion Kernel versions equal to and below xnu-1699.32.7 except xnu-1699.24.8 are affected.
7dda844fc6c2159587750ff9bbb7d5956502e05e69840baeb969d48120b1443f
VideoWhisper version 7 for Drupal suffers from a cross site scripting vulnerability.
3cb36f0f355441197eacc71c9ca9d019691be0cbec19e7c31df8fb082d3eb583
Depot WiFi version 1.0.0 for iOS suffers from code execution and local file inclusion vulnerabilities.
239876a4258fa1ffcf2718fcb13020b5cd7008ce28f17eef80d30d9eaea994bd
GeoCore MAX DB version 7.3.3 suffers from a time-based remote blind SQL injection vulnerability.
64ba7edde32456837b3726c9218f6cbada0d228c7d4a3ff8408e3d7216df33dc
WordPress iMember360is plugin versions 3.8.012 through 3.9.001 suffers from arbitrary code execution, database credential disclosure, arbitrary user deletion, and cross site scripting vulnerabilities.
4d85f0311356c907bff3b2196646e771d62abcd6b04f759570f4f0300a39cb77
WordPress Work-The-Flow plugin version 1.2.1 suffers from a remote shell upload vulnerability.
81151a69aad7d23a4b3ad3b647d219987ca81d347d7e6393e87eb89ac65182da
Kolibri version 2.0 GET request stack buffer overflow exploit that spawns a bindshell on TCP/4444.
329f1e7a41c16584e5af9f1499b811f888b81bccdba1aee77683cad9955bd7b6
InfraRecorder version 0.53 suffers from a unicode buffer overflow vulnerability.
0b8679268a6b10a4b2a1deab7b8b065f4eb7d1e739f4942337e4e38231c083d0
The WordPress Echelon theme suffers from a remote shell upload vulnerability.
c33b258feee36d875dc4c0082563970e58db338744d94505982121e9877a3449
xnews version 3-0-0 suffers from a cross site scripting vulnerability.
cb801e3e008731eae78be6fac9fbc8ace62b194df563ec4abc47db0f3fbefd09