Loggix Project version 9.4.5 and below is vulnerable to multiple remote file include vulnerability. The vulnerable files are Calendar.php, Comment.php, Rss.php, Trackback.php and LM_Downloads.php. The vulnerability exists in the require_once $pathToIndex . '/lib/Loggix/Module.php'; statement. An attacker can exploit this vulnerability by sending a malicious URL to the vulnerable application. The malicious URL contains the path to the attacker's malicious file which will be included in the vulnerable application.
ProdLer is vulnerable to a remote file include vulnerability. This vulnerability exists due to insufficient sanitization of user-supplied input in the 'sPath' parameter of 'prodler.class.php' script. An attacker can exploit this vulnerability to include arbitrary files from remote locations by using directory traversal techniques. This can potentially allow an attacker to include malicious files from remote locations and execute arbitrary code on the vulnerable system.
An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The attacker can inject malicious SQL queries in the vulnerable parameter and gain access to the database.
A vulnerability exists in cP Creator v2.7.1 which allows an attacker to inject malicious SQL queries into the application. This can be exploited to gain access to the application's database and potentially gain access to sensitive information. The vulnerability is due to insufficient sanitization of user-supplied input in the 'page' and 'task' parameters of the 'support' page. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL queries.
BAROSmini is prone to multiple remote file-inclusion vulnerabilities because it fails to sufficiently sanitize user-supplied input.
A SQL injection vulnerability exists in Joomla com_jbudgetsmagic component versions 0.3.2 - 0.4.0. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the back-end database.
Multiple Remote File Inclusion vulnerabilities exist in DDL CMS 1.0. An attacker can exploit these vulnerabilities by sending a specially crafted HTTP request containing malicious code in the 'wwwRoot' parameter of the vulnerable scripts. This malicious code will be executed on the server.
A SQL injection vulnerability exists in Joomla com_surveymanager component. An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. The vulnerability is due to the 'stype' parameter in the 'editsurvey' task of the 'com_surveymanager' component not properly sanitizing user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. Successful exploitation of this vulnerability can result in unauthorized access to the database and execution of arbitrary SQL commands.
FSphp 0.2.1 is vulnerable to multiple remote file inclusion vulnerabilities. An attacker can exploit these vulnerabilities by sending a malicious URL to the vulnerable application. The malicious URL contains the path of the malicious file which is hosted on a remote server. When the vulnerable application includes the malicious file, the attacker can execute arbitrary code on the vulnerable system.
The vulnerability exists due to insufficient sanitization of the listingid variable in the show-cat.php file. An attacker can inject their malicious SQL code and gain access to sensitive information such as user credentials, database information, and version information.