header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

SQL Injection in Z-Vote WordPress Plugin

The vulnerability exists due to failure in the "/zvote.php" script to properly sanitize user-supplied input in "zvote" variable. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

persistant xss in bitweaver2.8.1

A persistent XSS vulnerability exists in Bitweaver 2.8.1. An attacker can exploit this vulnerability by submitting an article with malicious JavaScript code in the author_name field. When an admin logs in and visits the Articles Home page, the malicious code will be executed. Additionally, when Bitweaver is running in test mode, an attacker can exploit an SQL injection vulnerability by visiting certain URLs with malicious parameters.

tplSoccerStats (player.php) Sql Injection Vulnerability

tplSoccerStats is vulnerable to SQL injection. An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. The vulnerability is caused due to the improper sanitization of user-supplied input in the "id" parameter of the "player.php" script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL statements to the vulnerable script.

sql injection in dotproject 2.1.5

A SQL injection vulnerability exists in dotproject 2.1.5. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data. The vulnerability is located in the fileviewer.php file, where the application is vulnerable to an unauthenticated SQL injection attack. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands on the underlying database, potentially allowing them to access sensitive data.

Local File Include in Galilery 1.0

Galilery 1.0 is vulnerable to a Local File Inclusion vulnerability. This vulnerability allows an attacker to include a file from a remote server, which can be used to execute malicious code on the vulnerable server. The vulnerability exists due to the fact that the application does not properly validate user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious file path.

SQL and XSS in DIY Web CMS

The DIY Web CMS is vulnerable to both SQL Injection and Cross-Site Scripting (XSS). An attacker can inject malicious SQL code into the 'menuid' parameter of the 'template.asp' page, as well as the 'id' parameter of the 'viewcatalog.asp' and 'xxx.asp' pages. Additionally, an attacker can inject malicious JavaScript code into the 'msg' parameter of the 'login.asp' page.

Recent Exploits: