Linux/x86 – Chmod + Execute (/usr/bin/wget http://192.168.1.93//x) + Hide Output Shellcode (129 bytes)
Windows/x86 – Start iexplore.exe (http://192.168.10.10/) Shellcode (191 Bytes)
D-Link models DIR-652, DIR-615, DIR-827, DIR-615, DIR-657, and DIR-825 suffer from an administrative password disclosure vulnerability.
Linux/x86 – ASCII AND, SUB, PUSH, POPAD Encoder Shellcode
Windows/x86 – bitsadmin Download and Execute (http://192.168.10.10/evil.exe “c:evil.exe”) Shellcode (210 Bytes)
Spidermonkey IonMonkey incorrectly predicts return type of Array.prototype.pop, leading to type confusion vulnerabilities.
SuperDoctor5 implemented a remote command execution plugin in their implementation of NRPE that can be leveraged without authentication.
SAPIDO RB-1732 version 2.0.43 suffers from a remote command execution vulnerability.
WordPress iLive plugin version 1.0.4 suffers from a cross site scripting vulnerability.
WordPress Live Chat Unlimited plugin version 2.8.3 suffers from a persistent cross site scripting vulnerability.