A vulnerability in Jadu® Galaxies allows an attacker to inject malicious SQL queries via the 'categoryID' parameter in the 'documents.php' script. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. This vulnerability was discovered by ZoRLu and was published on 17.11.2008.
Chilkat Software, Inc. has a vulnerable DLL, ChilkatSocket.DLL, with version 2,3,1,1. The Object Safety Report for Clsid: {474FCCCD-1B89-4D34-9E09-45807F23289C} shows that RegKey Safe for Script and Init is Faux, Implements IObjectSafety is Vrai, IDisp Safe is Safe for untrusted: caller,data, IPersist Safe is Safe for untrusted: caller,data, and IPStorage Safe is Safe for untrusted: caller,data. An exploit was created by Underz0ne Crew and Zigma, which creates an arbitrary file using a VBScript. The homepage of the exploit is http://www.underz0ne.org.
A remote login bypass vulnerability exists in Q-Shop v 3.0 (Maybe prior versions also). An attacker can send a specially crafted HTTP request to the vulnerable application in order to bypass authentication and gain access to the application.
This exploit allows an attacker to retrieve the admin password of the FREEze Greetings 1.0 application. The exploit works by decoding the contents of the pwd.txt file located in the target application's directory. The file contains a base64 encoded string which is then decoded to reveal the admin password.
A Blind SQL Injection vulnerability was discovered in E-topbiz AdManager 4 (group). An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'group' parameter of the 'view.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL code to the vulnerable script. Successful exploitation of this vulnerability can result in unauthorized access to the database and execution of arbitrary SQL commands.
OpenASP <= 3.0 is vulnerable to Blind SQL Injection. An attacker can inject malicious SQL queries into the vulnerable application and execute them in the backend database. This can be exploited to gain unauthorized access to the database and potentially gain access to sensitive data.
A cross-site scripting vulnerability exists in Microsoft Internet Explorer 7.0.5730.13. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in dynamically generated content. An attacker can exploit this issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable script. The crafted request contains malicious SQL statements that are appended to the existing SQL query. This can be used to bypass authentication, access, modify and delete data within the database.
Multiple SQL Injection vulnerabilities exist in Flosites Blog. An attacker can exploit these vulnerabilities by sending malicious SQL queries to the vulnerable application. This can be done by sending a specially crafted HTTP request to the vulnerable application. The attacker can use the UNION operator to extract data from the database. The attacker can also use the SQL injection vulnerability to execute administrative operations on the database such as shutdown the DBMS or dump the database content to the attacker.
Alfons Luja discovered a vulnerability in MiniGal b13, which can be exploited by malicious people to disclose potentially sensitive information. The vulnerability is caused due to the application not properly sanitizing user-supplied input to the 'list' parameter in 'index.php'. This can be exploited to disclose the source code of arbitrary files via a directory traversal attack.