header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Advanced Electron Forum Cross-Site Scripting Vulnerability

Advanced Electron Forum (AEF) is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

Host Directory PRO Security-Bypass Vulnerability

Host Directory PRO fails to properly validate user credentials before performing certain actions, allowing an attacker to bypass certain security restrictions and gain administrative access to the application. This can be done by setting a cookie with the value 'adm=1 path=/'.

XOOPS Recette SQL Injection Vulnerability

XOOPS Recette is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Azureus HTML WebUI Cross-Site Request-Forgery Vulnerability

Azureus HTML WebUI is prone to a cross-site request-forgery vulnerability. Successful exploits aid in transferring malicious content to unsuspecting users' computers, aiding in further attacks. Other actions may also be affected, but this has not been confirmed.

uTorrent WebUI Cross-Site Request-Forgery Vulnerability

uTorrent WebUI is prone to a cross-site request-forgery vulnerability. Exploiting this issue may allow a remote attacker to execute arbitrary actions in the context of the affected application. To force a file download, an attacker can send a malicious URL to the victim, such as http://www.example.com:8080/gui/?action=add-url&s=http://localhost/backdoor.torrent. To change administrative credentials and settings, an attacker can send malicious URLs such as http://www.example.com:8080/gui/?action=setsetting&s=webui.username&v=badmin, http://www.example.com:8080/gui/?action=setsetting&s=webui.password&v=badmin, http://www.example.com:8080/gui/?action=setsetting&s=webui.port&v=4096, and http://www.example.com:8080/gui/?action=setsetting&s=webui.restrict&v=127.0.0.1/24,10.1.1.1/24.

TorrentFlux Cross-Site Request-Forgery and Remote PHP Code-Execution Vulnerabilities

TorrentFlux is prone to a cross-site request-forgery vulnerability and a remote PHP code-execution vulnerability. Exploiting these issues may allow a remote attacker to create administrative accounts in the application or to execute arbitrary PHP script code. This may facilitate the remote compromise of affected computers. An example exploit code is provided which can be used to create an administrative account.

Wikepage Opus Cross-Site Scripting Vulnerability

Wikepage Opus is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

Recent Exploits: