header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

MyPHP Forum <= 3.0 (Final) Multiple Remote SQL Injection Vulnerability

The MyPHP Forum script version 3.0 (Final) is vulnerable to multiple remote SQL injection vulnerabilities. The first vulnerability exists in the faq.php file, where the 'id' parameter is not properly sanitized before being used in an SQL query. An attacker can exploit this vulnerability to execute arbitrary SQL queries. The second vulnerability exists in the member.php file, where the 'member' parameter is not properly sanitized before being used in an SQL query. An attacker can exploit this vulnerability to execute arbitrary SQL queries.

PHPKB Multi-Language 9 – Authenticated Remote Code Execution

This exploit allows an authenticated user to execute remote code in PHPKB Multi-Language 9. By manipulating the 'putdown_for_maintenance' parameter in the 'save-settings.php' file, an attacker can execute arbitrary commands.

IPTBB <= 0.5.4 Remote Sql Injection

The IPTBB forum system built using PHP and MySQL is vulnerable to remote SQL injection. By manipulating the 'id' parameter in the 'viewdir' action of the 'index.php' file, an attacker can execute arbitrary SQL queries. The exploit allows an attacker to retrieve sensitive information such as usernames, passwords, email addresses, and MSN accounts from the 'iptbb_users' table. The default admin id is 1, but any user id can be targeted.

ASUS AAHM 1.00.22 – ‘asHmComSvc’ Unquoted Service Path

A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.

Recent Exploits: