header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Multiple Vulnerabilities in Parallels® Plesk Sitebuilder

Bypass Loginpage: Change the URL path to http://victim.com:2006/wizard. Uploading Shell: Rename the shell to shell.asp.gif and capture data with Live HTTP Headers. Replay data with Live HTTP Headers and change the Content-Disposition to shell.asp.asp. Arbitrary File Download: You can download any file from your target by using the URL http://victim.com:2006/Wizard/EditPage/ImageManager/Site.ashx?s=GUID Sitename created&p=filename

WordPress WP Support Plus Responsive Ticket System 2.0 Plugin – Multiple Vulnerabilities

This plugin adds to WordPress the features of a complete ticket system with 100% responsive and 100% Ajax functionality. This allows users to submit tickets to report problems or get support on whatever they want. Users can set the status, priority and category of each ticket. SQL Injection can be done by sending a POST request to admin-ajax.php with action=openTicket&ticket_id=-1 UNION SELECT concat_ws(0x3a,version(),database(),user()),2,3,4,5,6,7. Full Path Disclosure can be done by sending a GET request to downloadAttachment.php with path=/var/www/wp-content/uploads/2014/09/file.pdf or path=. Directory Traversal can be done by sending a GET request to downloadAttachment.php with path=/etc/passwd. Broken Authentication can be done by sending a GET request to downloadAttachment.php with any file path.

PHP Stock Management System 1.02 – Multiple Vulnerabilty

XSS: An attacker can inject malicious JavaScript code into the 'msg' parameter of the 'install.php' page. SQL Injection: An attacker can inject malicious SQL code into the 'q' parameter of the 'stock.php' page and the 'searchtxt' parameter of the 'view_customers.php' page.

Atmail Webmail =>7.2 – Multiple XSS & FPD

Atmail Webmail versions 7.2 and below are vulnerable to multiple XSS and FPD. The XSS vulnerabilities can be exploited by sending a malicious request to the server. The FPD vulnerability can be exploited by sending a GET request to the server. The Persistent XSS vulnerability can be exploited by sending a GET request to the server.

TP-LINK Model No. TL-WR841N / TL-WR841ND – Multiple Vulnerabilities

Variables of ssid parameters are being included to wlanPara array. Because of poor filtration of those values, it is able to execute specific javascript command. While system log and config is being saved as local file, it is able to hjiack both via xss. Same as above, variable of pskSecret (password) is being included in javascript array. Because of no CSRF prevention, it is able to change the password by visiting url below.

TP-LINK Model No. TL-WR340G/TL-WR340GD – Multiple Vulnerabilities

Persistent Cross Site Scripting vulnerabilities exists because of poor parameters filtration. Our value is stored in javascript array, since it's not correctly verified nor filtered, it is able to inject javascript code. It will be executed whenever user will visit specific settings page. Because of no CSRF prevention, it is able to compromise router. Attacker may force user to restore factory default settings, and then to turn on remote managment; in result, it will be able to log in using default username and password (admin:admin).

Zen Cart 1.5.3 – CSRF & Admin Panel XSS

Zen Cart 1.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) and Persistent Cross-Site Scripting (XSS). An attacker can delete an admin user by sending a malicious GET request to the profiles.php page with the action parameter set to delete and the profile parameter set to the user ID. An attacker can also reset the layout boxes to default by sending a malicious GET request to the layout_controller.php page with the action parameter set to reset_defaults. Additionally, an attacker can inject malicious JavaScript code into the media_types.php and media_manager.php pages by sending a malicious POST request with the media_name parameter set to the malicious code.

phpMyFAQ 2.8.X – Multiple Vulnerabilities

Administrator is able to view information about specific user session in 'Statistic' tab. Over there, you may find informations such as user ip, refferer and user agent. For example, to view informations about session with ID 1, you need visit following address: http://localhost/phpmyfaq/admin/?action=viewsession&id=1. Refferer and User Agent variables are not filtered, which allows attacker to inject javascript via those parameters. All you need to do, is to perform particular HTTP request which will contain javascript. For example, if you will produce hundrends of those request, there will be hundrends of Persistent XSS - Victim only needs to visit any of them. Administrator is also able to view or download FAQ data using few extensions (xhtml, xml, pdf). Because of no user restrictions, attacker may reproduce this vulnerability to perform those actions even without having an account.

Recent Exploits: