header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Insufficient Validation of Client-side Data in Ninja Blog

Due to insufficient validation of client-side data, an attacker can inject scripts directly into the file-based storage used for blog comments. This allows for XSS attacks where a malicious script is executed when the comment is viewed, or CSRF attacks where the user is redirected to a malicious website and performs unintended actions.

Simple PHP Newsletter 1.5 Local File Include Vulnerability

The Simple PHP Newsletter 1.5 script is vulnerable to local file inclusion. The vulnerability exists in the 'mail.php' and 'mailbar.php' files, where the 'olang' parameter is not properly sanitized before being used in a require statement, allowing an attacker to include arbitrary local files. By manipulating the 'olang' parameter, an attacker can include sensitive files, such as the '/etc/passwd' file, which may contain hashed passwords and other system information.

Savant web server Buffer Overflow Exploit

This is a buffer overflow exploit for the Savant web server. It allows an attacker to execute arbitrary code on the server. The exploit code is written in Python and targets a specific vulnerability in the server. It was discovered by Mati Aharoni and coded by Tal Zeltzer and Mati Aharoni. This exploit is for research purposes only and should not be used maliciously.

Recent Exploits: