header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Oracle Java storeImageArray() Invalid Array Indexing

Oracle Java versions prior to 7u25 suffer from an invalid array indexing vulnerability that exists within the native storeImageArray() function inside jre/bin/awt.dll. This vulnerability allows for remote code execution. User interaction is required for this exploit in that the target must visit a malicious page or open a malicious file.

D-Link Devices Unauthenticated Remote Command Execution

Different D-Link Routers are vulnerable to OS command injection via the web interface. The vulnerability exists in command.php, which is accessible without authentication. This module has been tested with the versions DIR-600 2.14b01, DIR-300 rev B 2.13. Two target are included, the first one starts a telnetd service and establish a session over it, the second one runs commands via the CMD target. There is no wget or tftp client to upload an elf backdoor easily. According to the vulnerability discoverer, more D-Link devices may affected.

Integrated CMS Saudi SQL Injection

Integrated CMS Saudi is prone to a SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to view sensitive data in the back-end database, modify data, compromise the integrity of the database, execute administration operations on the database and issue commands to the operating system. This vulnerability affects version 1 of Integrated CMS Saudi.

Gnew v2013.1 Multiple XSS And SQL Injection Vulnerabilities

Gnew v2013.1 is vulnerable to multiple XSS and SQL injection vulnerabilities. Input passed via several parameters is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and HTML/script code in a user's browser session in context of an affected site.

Ajax PHP Penny Auction 1.x 2.x multiple Vulnerabilities

Ajax PHP Penny Auction is vulnerable to XSS, Information Disclosure, Blind SQL Injection and File Upload. XSS can be exploited by sending a malicious payload to the vulnerable parameter in forgotpasswd.php. Information Disclosure can be exploited by accessing phpinfo.php. Blind SQL Injection can be exploited by sending a malicious payload to the vulnerable parameter in item.php. File Upload can be exploited by getting the admin password and accessing homedesign.php.

PhpVID Script, Multiple Vulnerabilities

The PhpVID Script is vulnerable to multiple vulnerabilities such as SQL Injection, XSS and CRLF Injection. The SQL Injection vulnerabilities can be exploited by passing malicious payloads in the 'cat' and 'n' parameters of the browse_videos.php, groups.php and members.php files. The XSS vulnerability can be exploited by passing malicious payloads in the 'cat', 'n' and 'query' parameters of the browse_videos.php, groups.php and search_results.php files. The CRLF Injection vulnerability can be exploited by passing malicious payloads in the 'query' parameter of the search_results.php file.

MLMAuction Script, SQL Injection Vulnerabilities

MLMAuction Script is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Recent Exploits: