header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

AAA EasyGrid ActiveX v 3.51 Remote File Overwrite exploit

This exploit allows an attacker to overwrite a file on the victim's system with some HTML code. The vulnerability exists in the DoSaveFile() function of the AAA EasyGrid ActiveX v 3.51. The exploit has been tested on Windows XP Professional SP2 with Internet Explorer 6.

Joomla Component Fantasytournament Multiple SQL Injection Vulnerabilities

Multiple SQL Injection vulnerabilities exist in Joomla Component Fantasytournament. An attacker can exploit these vulnerabilities by sending malicious SQL queries to the vulnerable application. This can allow the attacker to access sensitive information from the database, such as usernames and passwords.

DoS code for Cisco VLAN Trunking Protocol Vulnerability

This exploit is for a vulnerability in the Cisco VLAN Trunking Protocol (VTP). The vulnerability allows an attacker to send a malicious VTP packet to a Cisco switch, causing it to reload. The attacker must know the VTP domain of the switch, which can be sniffed. The exploit is written in C and requires the libnet library.

Joomla Component Camelcitydb2 SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. The attacker can inject arbitrary SQL code in the vulnerable parameter 'id' of the 'index.php' script. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. An example of a malicious request is '/index.php?option=com_camelcitydb2&id=-3+union+select+1,2,concat(username,char(58),password)KHG,4,5,6,7,8,9,10,11+from+jos_users--&view=detail&Itemid=15'

DMXReady Members Area Manager <= 1.2 SQL Injection Vulnerability

A SQL injection vulnerability exists in DMXReady Members Area Manager version 1.2 and earlier. An attacker can exploit this vulnerability to gain access to the admin panel and execute arbitrary SQL commands. The vulnerability is due to insufficient sanitization of user-supplied input in the 'cid' parameter of the 'upload_image_security_level.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands to the vulnerable script.

DMXReady Member Directory Manager <= 1.1 SQL Injection Vulnerability

A SQL injection vulnerability exists in DMXReady Member Directory Manager version 1.1. An attacker can exploit this vulnerability to gain access to the application's database and execute arbitrary SQL commands. The vulnerability is due to insufficient sanitization of user-supplied input in the 'cid' parameter of the 'upload_image_category.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands to the vulnerable script. Successful exploitation of this vulnerability can result in unauthorized access to the application's database and execution of arbitrary SQL commands.

DMXReady Links Manager <= 1.1 Remote Contents Change Vulnerability

A vulnerability in DMXReady Links Manager version 1.1 allows an attacker to remotely change the contents of the application. This is due to the lack of authentication and authorization checks in the add_category.asp page, which allows an attacker to insert, update, and delete categories and subcategories.

DMXReady Job Listing <= 1.1 Remote Contents Change Vulnerability

A vulnerability exists in DMXReady Job Listing version 1.1 which allows an attacker to remotely change the contents of the website. The vulnerability is due to the lack of proper authentication and authorization checks in the 'inc_joblistingmanager.asp' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable script. This can result in the attacker gaining access to the website and changing the contents of the website.

Recent Exploits: