Clean CMS 1.5 is vulnerable to Blind SQL Injection. This exploit uses a multi-threaded approach to extract data from the database. It uses the 'full_txt.php' page to extract data from the database. It takes the URL and HTML pattern as input and uses the LWP::UserAgent module to send requests to the server. It then uses the ASCII values of the characters to extract data from the database.
A vulnerability in FAQ Manager 1.2 allows remote attackers to include arbitrary files via a URL in the config_path parameter to include/header.php.
Clean CMS 1.5 is prone to multiple remote vulnerabilities, including blind SQL injection and cross-site scripting. An attacker can exploit these issues to execute arbitrary SQL commands in the context of the affected application, steal cookie-based authentication credentials, and launch other attacks. The demo URLs provided in the exploit code demonstrate the vulnerabilities.
An attacker can bypass authentication by using the username 'real_admin_name' ' or ' 1=1 and the password ZoRLu (or no password). Additionally, an XSS attack can be performed by using the URL http://www.arcade-classics.net/top100/index.php?start="><script>alert()</script>
This vulnerability allows attackers to obfuscate the URI of a website and redirect users to malicious websites. This is done by using the null character (%00) in the URI. This vulnerability affects Google Chrome versions 0.4.154.25 and below. It has been tested on Windows XP and Windows Vista.
Pie Web RSS module 0.1 (lib) is vulnerable to a remote file injection vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This can allow the attacker to inject arbitrary files on the vulnerable server.
A remote SQL injection vulnerability exists in FAQ Manager 1.2, due to insufficient sanitization of user-supplied input to the 'cat_id' parameter of the 'categorie.php' script. An attacker can exploit this vulnerability to gain access to the database, and can execute arbitrary SQL commands on the underlying database.
A Blind SQL Injection vulnerability exists in WebStudio eCatalogue, which allows an attacker to execute arbitrary SQL commands on the underlying database. The vulnerability is due to insufficient sanitization of user-supplied input in the 'pageid' parameter of the 'index.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands. Successful exploitation of this vulnerability can result in unauthorized access to sensitive information, such as usernames and passwords, and modification of data in the database.
A Blind SQL Injection vulnerability exists in WebStudio eHotel, which allows an attacker to execute arbitrary SQL commands on the underlying database. The vulnerability is due to insufficient input validation of the 'pageid' parameter in the 'index.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands. Successful exploitation of this vulnerability can result in unauthorized access to sensitive information, such as user credentials, and other data stored in the database.
Pie Web M{a,e}sher version 0.5.3 is vulnerable to a Remote File Inclusion vulnerability. All files below are affected by the 'lib' parameter: lib/action/alias.php, lib/action/cancel.php, lib/action/context.php, lib/action/deadlinks.php, lib/action/delete.php, lib/action/diff.php, lib/action/download.php, lib/action/dump.php, lib/action/edit.php, lib/action/fileimport.php, lib/action/fileinfo.php, lib/action/filelist.php, lib/action/goto.php, lib/action/history.php, lib/action/image.php, lib/action/latest.php, lib/action/links.php, lib/action/logflush.php, lib/action/login.php, lib/action/logout.php, lib/action/logshow.php, lib/action/maintenance.php, lib/action/page.php, lib/action/pageimport.php, lib/action/pageinfo.php, lib/action/pagelist.php, lib/action/password.php, lib/action/preview.php, lib/action/purge.php, lib/action/referers.php, lib/action/register.php, lib/action/rename.php, lib/action/revert.php, lib/action/rss.php, lib/action/search.php, lib/action/show.php, lib/action/source.php, lib/action/systeminfo.php, lib/action/update.php, lib/action/upgrade.php, lib/action/upload.php, lib/action/useradd.php, lib/action/userdel.php, lib/action/useredit.php, lib/action/userimport.php, lib/action/li