header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Epicor Enterprise vulnerabilities

There are two vulnerabilities affecting Epicor Enterprise version 7.4. The first vulnerability, CVE-2014-4311, allows for password values to be accessed by observing the HTML code. The affected password values are 'Database Connection' and 'E-mail Connection'. The second vulnerability, CVE-2014-4312, allows for persistent and reflective cross-site scripting (XSS) attacks. This vulnerability allows for script injection and can result in abnormal behavior of the application.

Cross-Site Scripting Vulnerabilities in HP Insight Diagnostics Online Edition

The HP Insight Diagnostics Online Edition is vulnerable to multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities occur due to improper sanitization of user-supplied input. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user, potentially leading to the theft of authentication credentials and other attacks.

Inclusion Vulnerability in WORK system e-commerce

The WORK system e-commerce PHP application is vulnerable to an inclusion vulnerability. The vulnerable script is 'include_top.php', which is part of the content management system (CMS) for e-commerce. The vulnerability allows an attacker to include arbitrary files by manipulating the 'g_include' parameter in the URL. An example proof-of-concept (PoC) URL is provided in the text. The vulnerability can be exploited to execute malicious code or disclose sensitive information.

Grafik CMS SQL Injection and Cross-Site Scripting Vulnerabilities

The Grafik CMS is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities due to inadequate sanitization of user-supplied input. Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Recent Exploits: