This vulnerability allows an attacker to execute SQL queries on the database without the need for authentication. By injecting malicious SQL code into the 'user_id' parameter, an attacker can retrieve sensitive information from the database.
Multiple remote vulnerabilities in Gyro V5.0 allow attackers to execute arbitrary SQL commands or inject arbitrary web script or HTML via the cid parameter in (1) home or (2) op in home.php.
This is an exploit for the vulnerability discovered in Pidgin by core-security. The library "libmsn" used by pidgin doesn't handle specially crafted MsnSlp packets which could lead to memory corruption.
The Modern Script 5.0 index.php file is vulnerable to a remote SQL injection attack. By manipulating the 's' parameter in the URL, an attacker can execute arbitrary SQL queries on the database.
This exploit demonstrates the exploitability of the sock_sendpage() NULL pointer dereference vulnerability on ppc and ppc64 architectures. It utilizes the SELinux and mmap_min_addr issues to exploit the vulnerability on Red Hat Enterprise Linux 5.3 and CentOS 5.3. The vulnerability affects Linux kernel versions from 2.4.4 to 2.4.37.4, and from 2.6.0 to 2.6.30.4.
The validation of some ftp commands are not made by the server. This leads to a DoS.
The File System Filter driver in avast! 4.8.1335 Professionnel is prone to a local kernel buffer overflow vulnerability. This allows an intruder to gain SYSTEM privileges on a Windows system from a limited user account.
This exploit allows an attacker to execute arbitrary code by exploiting a buffer overflow vulnerability in ProShow Gold 4.0. The vulnerability is triggered when processing a specially crafted show file.
This is an exploit for the Traidnt UP v2.0 script that allows for SQL injection. The exploit was discovered and written by Jafer Al-Zidjali. The vulnerability occurs when the magic_quotes_gpc setting is turned off. The author has been notified and a public patch has been released for this vulnerability.
This vulnerability allows an attacker to inject SQL queries into the application's database, potentially gaining unauthorized access or modifying data.