header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

PHP ZLink v0.3 Remote SQL Injection

The PHP ZLink v0.3 (go.php) script is vulnerable to SQL Injection. The script fails to properly sanitize user input in the 'id' parameter, allowing an attacker to manipulate the SQL query and extract sensitive information from the database. By crafting a specially crafted request, an attacker can bypass authentication and retrieve the usernames and passwords from the 'admin' table. This vulnerability was discovered by DNX.

Anviz CrossChex 4.3.12 – Local Buffer Overflow

The Anviz CrossChex software version 4.3.12 is vulnerable to a local buffer overflow. This vulnerability can be exploited by an attacker to execute arbitrary code or crash the software.

Nsauditor 3.1.8.0 – ‘Key’ Denial of Service (PoC)

This exploit creates a Denial of Service (DoS) attack on Nsauditor version 3.1.8.0. It involves creating a file with a payload that causes the software to crash when the content of the file is pasted into the 'Key' field during registration.

Dokuwiki 2018-04-22b – Username Enumeration

The Dokuwiki version 2018-04-22b 'Greebo' allows for username enumeration through the 'set new password' page. By testing for non-valid usernames, it is possible to determine whether a user exists in the database. The vulnerability can be exploited by sending a POST request to the /doku.php?id=start&do=resendpwd endpoint.

Recent Exploits: