A vulnerability exists in the RS MAXSOFT web application which allows an attacker to inject malicious SQL queries via the 'fotoID' parameter in the 'modules/fotogalerie/popup_img.php' script. This can be exploited to gain access to the admin panel by using the 'union select' statement to concatenate the login and password from the 'admin' table.
LightNEasy 1.2 no database is vulnerable to a hash disclosure vulnerability. The vulnerability is due to the fact that the application does not properly sanitize user-supplied input to the 'do' parameter of the LightNEasy.php script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This will allow the attacker to retrieve the admin's SHA1 hash.
Ksemail is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to view sensitive files on a vulnerable computer in the context of the webserver process. This may facilitate unauthorized access. http://site.com/prog/index.php?language=../../../../../../etc/passwd http://site.com/prog/index.php?lang=../../../../../../etc/passwd Dork example: "FoxMail/Outook"
Livecart Remote Blind Sql Injection is a vulnerability that allows an attacker to inject malicious SQL code into a vulnerable web application. This vulnerability can be exploited to gain access to sensitive data stored in the database, such as user credentials, or to modify the data stored in the database. The vulnerability is caused by improper input validation and can be exploited by sending specially crafted SQL queries to the vulnerable web application.
KnowledgeQuest 2.6 is vulnerable to SQL injection. An attacker can exploit this vulnerability to gain access to the database and extract sensitive information. The vulnerability exists in the articletext.php and articletextonly.php scripts. An attacker can exploit this vulnerability by sending a specially crafted HTTP GET request with a malicious SQL query. The vulnerable code is present in the logincheck.php script, which allows an attacker to bypass authentication by sending a specially crafted HTTP POST request with a malicious SQL query.
A Remote File Disclosure vulnerability exists in showSource.php of phaos4.0.1. The vulnerability is due to the application not properly sanitizing user-supplied input to the 'file' parameter of the showSource.php script. This can be exploited to disclose the contents of arbitrary files on the affected system by passing a specially crafted URL to the vulnerable script.
A Remote Local File Inclusion vulnerability exists in the ARWScripts Gallery Script Lite, which allows an attacker to include a file from a remote server. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious file path to the vulnerable application. This can result in the execution of arbitrary code on the vulnerable system.
This exploit will craft a evilpacket which will add a admin account to the KnowledgeQuest 2.5 application.
An ActiveX control in IBiz E-Banking Integrator V2 allows remote attackers to write arbitrary files via the WriteOFXDataFile method.
This exploit allows an attacker to execute arbitrary code on the vulnerable server by including a remote file. The vulnerability exists due to the $phpbb_root_path variable not being declared before the include statement in line 21 of functions_portal.php. This allows an attacker to inject arbitrary code into the application and execute it on the server.