header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Gnuboard HTML-injection Vulnerability

Gnuboard is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user.

TYPSoft FTP Server Buffer Overflow Vulnerability

TYPSoft FTP Server is prone to a buffer-overflow vulnerability. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. TYPSoft FTP Server 1.1.0 is vulnerable; other versions may also be affected.

JavaBB Cross-Site Scripting Vulnerability

JavaBB is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

JPM Article Script 6 SQL Injection Vulnerability

JPM Article Script 6 is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Citrix Licensing Denial-of-Service Vulnerability

Citrix Licensing is prone to a denial-of-service vulnerability. A remote attacker can leverage this issue to crash the affected application, denying service to legitimate users. Proof-of-Concept: http://www.example.com/users?licenseTab=&selected=&userName=xsrf&firstName=xsrf&lastName=xsrf&password2=xsrf&confirm=xsrf&accountType=admin&originalAccountType=&Create=Save(Administrator CSRF) http://www.example.com/dashboard?<something long here>=2 (pre auth DoS, crashes lmadmin.exe)

Max’s PHP Photo Album Local File-Include Vulnerability

Max's PHP Photo Album is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process.

Max’s Guestbook Multiple Remote Vulnerabilities

Max's Guestbook is prone to multiple remote vulnerabilities. Exploiting these issues could allow an attacker to execute arbitrary HTML and script code in the context of the affected browser, steal cookie-based authentication credentials, and execute arbitrary local scripts in the context of the webserver process. Other attacks are also possible.

Light Display Manager (LightDM) Local Arbitrary File Deletion Vulnerability

Light Display Manager (LightDM) is prone to a local arbitrary-file-deletion vulnerability. A local attacker can exploit this issue to delete arbitrary files with administrator privileges. Light Display Manager (LightDM) 1.0.6 is vulnerable. Other versions may also be affected. The vulnerability is caused by the /usr/sbin/guest-account script, which runs with the cwd of the last logged in user. If the user creates a file '/tmp/x a', the file 'a' gets removed from the last user's login.

Omnistar Live SQL-injection and Cross-site Scripting Vulnerabilities

Omnistar Live is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Recent Exploits: