header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

PastelCMS 0.8.0 (LFI/SQL) Multiple Remote Vulnerabilities

PastelCMS 0.8.0 is vulnerable to Local File Inclusion and SQL Injection. The Local File Inclusion vulnerability can be exploited by sending a specially crafted HTTP request containing directory traversal characters. The SQL Injection vulnerability can be exploited to bypass authentication by sending a specially crafted HTTP request containing malicious SQL code.

Powered By eLitius 1.0 Remote Database Backup

eLitius 1.0 is prone to a remote vulnerability that allows attackers to download the database backup. This vulnerability is due to a lack of authentication in the 'database-backup.php' script. An attacker can exploit this issue to download the database backup without authentication.

e107 <= 0.7.15 "extended_user_fields" Blind SQL Injection Exploit

e107 contains one flaw that allows an attacker to carry out an SQL injection attack. The issue is due to the "usersettings.php" script not properly saniting user-supplied input to the hide[] key. This may allow an attacker to inject or manipulate sql queries in the backend database if magic_quotes_gpc = off.

Simpoe Event Calendar Remote File Include Vulnerability

Simpoe Event Calendar is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to execute arbitrary PHP code within the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

Insecure cookie handling BLIND SQL INJECTION

WysGui CMS 1.2 BETA is vulnerable to Blind SQL Injection. The vulnerability is located in the 'cookie' parameter of the 'index.php' file. Remote attackers can inject own SQL commands to compromise the web application. The injection point is the 'cookie' parameter and the execution point is in the 'index.php' file. The exploitation is possible without authentication. Successful exploitation of the vulnerability results in database management system compromise.

Recent Exploits: