Attacker can create user and host on the target system by exploiting the vulnerability in the admin/hosting/addsubsite.asp page.
This HTML page includes a JavaScript file from a GitLab repository. The specific JavaScript file is 986.js (also known as 05072005.js) and it is loaded using the script tag. The purpose and functionality of this script are unknown as the code is not provided in the given text. The author of this HTML page is mentioned as 'str0ke'.
The worm exploits a vulnerability in ZeroBoard, allowing an attacker to inject arbitrary PHP code.
This module exploits a code execution exploit in wordpress blog <= 1.5.1.3.
The form action attribute is manipulated to send form data to an external page.
This module exploits an arbitrary PHP code execution flaw in the vBulletin web forum software. This vulnerability is only present when the 'Add Template Name in HTML Comments' option is enabled. All versions of vBulletin prior to 3.0.7 are affected.
This module exploits an arbitrary PHP code execution flaw in the WordPress blogging software. This vulnerability is only present when the PHP 'register_globals' option is enabled (common for hosting providers). All versions of WordPress prior to 1.5.1.3 are affected.
Previews on comments were not passed through normal form validation routines, enabling users with the 'post comments' permission and access to more than one input filter to execute arbitrary code. By default, anonymous and authenticated users have access to only one input format.
Previews on comments were not passed through normal form validation routines, enabling users with the 'post comments' permission and access to more than one input filter to execute arbitrary code. By default, anonymous and authenticated users have access to only one input format. Immediate workarounds include: disabling the comment module, revoking the 'post comments' permission for all users or limiting access to one input format.
This exploit allows an attacker to perform a denial of service attack on Serv-u FTP server versions up to 5.2. By sending a specially crafted request, the server crashes, resulting in a denial of service for legitimate users.