header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

HostBill Authentication Bypass Vulnerability

HostBill is prone to an authentication-bypass vulnerability. Attackers can exploit this issue to gain unauthorized access to the affected application and disclose sensitive information. An attacker can exploit this issue by sending a specially crafted HTTP request to the vulnerable application. This request contains a malicious URL that includes a 'do' parameter set to 'backup' and a 'filename' parameter set to '../templates_c/DB_Dump.txt'. The 'login_username' and 'password' parameters are set to '0'.

Category Grid View Gallery Plugin for WordPress Cross-Site Scripting Vulnerability

The Category Grid View Gallery plugin for WordPress is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

WP Feed plugin for WordPress SQL-injection Vulnerability

WP Feed plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Xorbin Digital Flash Clock Plugin for WordPress Cross-Site Scripting Vulnerability

The Xorbin Digital Flash Clock plugin for WordPress is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Xorbin Analog Flash Clock Plugin Cross-Site Scripting Vulnerability

The Xorbin Analog Flash Clock plugin is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Atomy Maxsite Arbitrary File Upload Vulnerability

Atomy Maxsite is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input. An attacker can exploit this issue to upload arbitrary code and execute it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

WP Private Messages plugin for WordPress SQL-injection Vulnerability

WP Private Messages plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Recent Exploits: