The vulnerability exists due to insufficient sanitization of user-supplied input in the 'Path' parameter of the 'members/admin.txt' script. A remote attacker can gain access to arbitrary files on the vulnerable system.
A remote file include vulnerability exists in i-dreams.net GB Server, which allows an attacker to include a remote file containing malicious code on the vulnerable server. This can be exploited to execute arbitrary PHP code on the vulnerable server.
This vulnerability allows remote attackers to execute arbitrary PHP code on vulnerable installations of i-dreams.net GB 5.4 Final. Authentication is not required to exploit this vulnerability. The specific flaw exists within the 'firebook/data/admdat/admin.dat' script. This script fails to properly sanitize user-supplied input to the 'page' variable. An attacker can leverage this vulnerability to execute arbitrary PHP code under the context of the webserver.
This vulnerability allows remote attackers to include and execute arbitrary local or remote files via a URL in the 'admin.dat' parameter in the 'cgi-bin/budmail/data/' directory.
A vulnerability was discovered in Got All Media 7.0.0.3 which allows a remote attacker to cause a denial of service. The vulnerability is due to an unspecified error when handling a specially crafted HTTP request. This can be exploited to cause a denial of service via a specially crafted HTTP request.
Bugged file is /[path]/smNews/login.php [...] register.php. Exploit: 1- Username: admin ' or ' Password: x0r 2- You have only to re-reg the admin.. ex: (if admin nick is 'lol' you reg an account with your passwd, email and nick 'lol' ^^ easy :P
Firepack is a web atting toolkit often used in 2008, when the most versions of it were published. A short time ago i looked though the sourcecode and noticed that Vulnerability which can be used if the admin doesn't use a .htaccess protection in his admin area. WARNING: When accessing the index.php, malware could be executed so i recommend to execute it in a virtual environment. Username and password are located in config.php in the main folder.
This module will escalate a Oracle DB user to MDSYS by exploiting an sql injection bug in the MDSYS.SDO_TOPO_DROP_FTBL trigger. After that exploit escalate user to DBA using 'CREATE ANY TRIGGER' privilege given to MDSYS user by creating evil trigger in system scheme (2-stage attack).
Bugged file is /[path]/extra/genbackup.php. Exploit: http://victim.org/extra/genbackup.php
An attacker can exploit this vulnerability by setting a cookie with the name 'login' and value 'OK' and then sending a malicious HTTP request to the vulnerable application. This will allow the attacker to delete any page from the application.