The vulnerability exists due to failure in the "/zvote.php" script to properly sanitize user-supplied input in "zvote" variable. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
A persistent XSS vulnerability exists in Bitweaver 2.8.1. An attacker can exploit this vulnerability by submitting an article with malicious JavaScript code in the author_name field. When an admin logs in and visits the Articles Home page, the malicious code will be executed. Additionally, when Bitweaver is running in test mode, an attacker can exploit an SQL injection vulnerability by visiting certain URLs with malicious parameters.
tplSoccerStats is vulnerable to SQL injection. An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. The vulnerability is caused due to the improper sanitization of user-supplied input in the "id" parameter of the "player.php" script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL statements to the vulnerable script.
An attacker can exploit this vulnerability by sending a crafted SQL query to the vulnerable parameter 'info' in the index.php file. This can allow the attacker to gain access to the database and extract sensitive information.
There is directory traversal vulnerability in the SideBooks. Exploit Testing involves connecting to the FTP server and using the 'cd ../../../../../../../' command to traverse the directory structure.
There is directory traversal vulnerability in the FtpDisc. Exploit Testing involves connecting to the FTP server using the command line and then using the 'cd' command to traverse the directory structure.
A SQL injection vulnerability exists in dotproject 2.1.5. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data. The vulnerability is located in the fileviewer.php file, where the application is vulnerable to an unauthenticated SQL injection attack. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data.
Galilery 1.0 is vulnerable to a Local File Inclusion vulnerability. This vulnerability allows an attacker to include a file from a remote server, which can be used to execute malicious code on the vulnerable server. The vulnerability exists due to the fact that the application does not properly validate user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious file path.
The DIY Web CMS is vulnerable to both SQL Injection and Cross-Site Scripting (XSS). An attacker can inject malicious SQL code into the 'menuid' parameter of the 'template.asp' page, as well as the 'id' parameter of the 'viewcatalog.asp' and 'xxx.asp' pages. Additionally, an attacker can inject malicious JavaScript code into the 'msg' parameter of the 'login.asp' page.
This exploit is a denial of service attack against Solar FTP 2.1. It sends a large number of packets to the server, causing it to crash. It was tested on Windows XP SP3 Portuguese Brazilian.