header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

MIMEsweeper for SMTP Cross-Site Scripting Vulnerabilities

MIMEsweeper for SMTP is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Sonar Cross-Site Scripting Vulnerabilities

Sonar is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Path Disclosure Vulnerability in NextGEN Gallery Plugin for WordPress

The NextGEN Gallery plugin for WordPress is prone to a path-disclosure vulnerability. An attacker can exploit this issue to obtain sensitive information that may lead to further attacks. The vulnerability is triggered when an attacker sends a specially crafted request to the vulnerable application. This can be done by sending a request to the vulnerable application with the following parameters: http://www.example.com/?callback=json&api_key=true&format=json&method=gallery&id=1 and http://www.example.com/?callback=json&api_key=true&format=xml&method=recent&limit=1

Dell SonicWALL Scrutinizer HTML-injection Vulnerabilities

The Dell SonicWALL Scrutinizer is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input. Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

BlackNova Traders SQL-injection Vulnerability

BlackNova Traders is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

osCommerce Cross-Site Request-Forgery Vulnerability

osCommerce is prone to a cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests. Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.

TP-LINK TL-WR2543ND Multiple Cross-Site Request-Forgery Vulnerabilities

TP-LINK TL-WR2543ND is prone to multiple cross-site request-forgery vulnerabilities because the application fails to properly validate HTTP requests. Exploiting these issues may allow a remote attacker to change a device's configuration and perform other unauthorized actions.

Pinboard Theme for WordPress Cross-Site Scripting Vulnerability

The Pinboard theme for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Audio Player Plugin for WordPress Cross-Site Scripting Vulnerability

The Audio Player plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

xNBD Insecure Temporary File Handling

xNBD is prone to a vulnerability because it handles temporary files in an insecure manner. Local attackers may leverage this issue to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible. An attacker can create a symbolic link to a file they wish to overwrite, and then start the xNBD server. The server will then write to the file pointed to by the symbolic link, allowing the attacker to overwrite the file.

Recent Exploits: