TECHNOTE (VERSION 7.2 (08.09.25)) is bulletin board system of Korea. It is freely available for all platforms that supports PHP and MySQL. But I find Remote File Inclusion vulnerability. Here is the details: TEST ON VERSION TECHNOTE 7.2 (08.09.25) Download : http://www.technote.co.kr/ Remote File Inclusion Vulnerability /body_default.php if($GOODS['gs_input']) include "$shop_this_skin_path/2_view_body/include/form_option.php"; //File Include PoC: http://[site]/skin_shop/standard/2_view_body/body_default.php?GOODS[no]=deadbeef&GOODS[gs_input]=deadbeef&shop_this_skin_path=[RFI]
4Site CMS version 2.6 and below is vulnerable to multiple remote SQL injections. An attacker can bypass authentication by using '1'or'1' as the username and password. Additionally, the 'Pages', 'Portfolio', 'Hotels', 'News', and 'FAQ' modules are vulnerable to SQL injection attacks.
A vulnerability exists in MyDesing Sayac v2.0 which allows an attacker to bypass authentication by entering 'or' as the username and password. This allows the attacker to gain access to the admin panel.
Hex Workshop v6 is vulnerable to an invalid memory reference crash when a specially crafted .cmap file is opened. The vulnerability is caused due to a boundary error when handling the 'RGB' value of the .cmap file. This can be exploited to cause a denial of service when a user opens a specially crafted .cmap file.
WEBalbum v2.4b is vulnerable to Blind SQL Injection. An attacker can exploit this vulnerability to gain access to the database and extract sensitive information. This exploit is based on the difference in response time when a true and false statement is sent to the server.
A vulnerability exists in AJA Modules Rapidshare 1.0.0 which allows an attacker to upload a malicious shell to the server. The attacker can change the type of shell from c99.Php to c99.php.rar and upload it to the server. The uploaded file can be found in the images/files/c99.php.rar directory.
BBCode of the smf not filtered properly specified urls, allowing attackers to inject malicious JavaScript code. When the user clicks on the image, the malicious JavaScript code is executed. The malicious JavaScript code then calls a PHP script on the attacker's server, which steals the user's cookie and sends it to the attacker.
A local buffer overflow vulnerability exists in Euphonics Audio Player v1.0. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to a boundary error when handling .pls files. A specially crafted .pls file can cause a stack-based buffer overflow, overwriting the return address and allowing arbitrary code execution.
A vulnerability exists in Online Grades 3.2.4 which allows an attacker to bypass authentication and gain access to the phpinfo.php file. This is done by sending a specially crafted POST request to the login.php page with the username and password fields set to '[validemail] ' or ' 1=1--'
A vulnerability exists in GBOOK v2.0 which allows a remote attacker to include a file from a remote location. The vulnerability is due to the 'abspath' parameter in the 'header.php' script not properly sanitized before being used to include files. This can be exploited to include arbitrary files from remote locations by passing a URL in the 'abspath' parameter.