header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Guru JustAnswer Professional 1.25 Multiple SQL Injection Vulnerabilities

Guru JustAnswer Professional 1.25 is vulnerable to multiple SQL injection vulnerabilities. An attacker can exploit these vulnerabilities to gain access to sensitive information stored in the database, such as user credentials, or to execute arbitrary SQL commands.

Puzzle Apps CMS 3.2 Local File Inclusion

In Puzzle App CMS there are couple of the places you will be able to find LFI vulns. The vulnerable source is include_once ($COREROOT . "config/loader.config.php"); and the sample to LFI is http://localhost/puzzle/core/config.loader.php?COREROOT=[LFI] and the PoC LFI is http://localhost/puzzle/core/config.loader.php?COREROOT=../../../boot.ini%00

Joomla Component com_jmsfileseller Local File Inclusion Vulnerability

JMS FileSeller is vulnerable to a Local File Inclusion vulnerability. This vulnerability allows an attacker to include a file from the local file system of the server. The vulnerable parameter is 'view' and an example of the vulnerable URL is index.php?option=com_jmsfileseller&view=../../../etc/passwd%00&cat_id=12&Itemid=27

Guru Penny Auction Pro V3 Blind SQL Injection Vulnerability

Guru Penny Auction Pro V3 is vulnerable to Blind SQL Injection. An attacker can exploit this vulnerability to gain access to sensitive information from the database. The vulnerable parameter is 'prodid' which can be manipulated to inject malicious SQL queries. An attacker can use the SUBSTRING() function to extract information from the database.

Recent Exploits: