header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Siena CMS Cross-Site Scripting Vulnerability

Siena CMS is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

WordPress Download Manager 2.7.2 Privilege Escalation

Every registered user can update every WordPress options using basic_settings() function. Login as standard user (created using wp-login.php?action=register) then submit a form with a hidden input containing a value of 'administrator' for the 'default_role' parameter. After that create new user using wp-login.php?action=register. Newly created user will have admin privileges.

Photo Gallery 1.2.5 Unrestricted File Upload

Every registered user (even Subscriber) can access upload functionality because of read role used inside UploadHandler.php. A proof of concept is provided which involves packing .php files into a .zip archive and sending it using a form. The files will be visible inside a specified directory.

Recent Exploits: