phpMyBitTorrent is vulnerable to Local File Inclusion due to insufficient sanitization of user-supplied data. Attack vectors include user-supplied cookie parameters 'bttheme' and 'btlanguage' and user-supplied parameter 'theme_change'. Preconditions include magic_quotes_gpc=off and PHP must be < 5.3.4 for null-byte attacks to work.
Input passed via the "themes_editor" POST parameter to /admin/index.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in administrator's browser session in context of an affected website. The application allows authorized administrator to perform certain actions via HTTP requests without making proper validity checks to verify the source of the requests. This can be exploited to add, delete or modify sensitive information, for example to create new administrator or execute arbitrary PHP code.
XnView Formats PlugIn is prone to an overflow condition. The JLS Plugin (xjpegls.dll) library fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted JLS compressed image file, a context-dependent attacker could potentially execute arbitrary code.
The phpMyChat Plus v1.94 RC1 is vulnerable to Remote Blind SQL Injection, Remote File Inclusion, Local File Inclusion, and XSS. For Remote Blind SQL Injection, an attacker can use some automatic blind SQL injection to get database information. For Remote File Inclusion, the allow_url_include must be set to On. For Local File Inclusion, the magic_quotes_gpc must be set to Off. For XSS, an attacker must have a good brain.
The vulnerability is caused due to an indexing error in the "ShowPropertiesDialog()" method (ChartFX.ClientServer.Core.dll) of the ChartFX ActiveX Control. This can be exploited to write a single byte value to an arbitrary memory location via the "pageNumber" parameter. Successful exploitation may allow execution of arbitrary code.
Omnistar Mailer v7.2 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Spider Calendar is a highly configurable plugin which allows you to have multiple organized events in a calendar. This plugin is one of the best WordPress Calendar available in WordPress Directory. An XSS vulnerability exists in the plugin due to improper sanitization of user-supplied input in the 'calendar_id' and 'ev_ids' parameters of the 'spidercalendarbig.php' and 'spidercalendarbig_seemore.php' scripts. An attacker can exploit this vulnerability to execute arbitrary HTML and script code in a user's browser session in the context of the affected site. A SQL injection vulnerability exists in the plugin due to improper sanitization of user-supplied input in the 'calendar_id' parameter of the 'spidercalendarbig_seemore.php' script. An attacker can exploit this vulnerability to inject and execute arbitrary SQL commands in the database.
Soapbox allows to restrict processes to write only to those places you want. Read-access however is still based on file-permissions. By preloading the Soapbox library, you can run programs as root and monitor which writes/changes are made, without them really happening. After establishing a connection to our target system, we get a sandboxed root shell. Let's try to write data to a protected location. As we can see, soapbox restricts write access to this path. But what happens if we start another soapbox instance with full file-system access?
The application is prone to a remote code execution vulnerability. An attacker can exploit this issue by sending a specially crafted HTTP request containing malicious code to the vulnerable application. This may allow the attacker to execute arbitrary code in the context of the vulnerable application.
This exploit allows an attacker to change the configuration of the Archin WordPress Theme without authentication. The attacker can change the admin email, enable user registration, and set the default role to administrator. This allows the attacker to register a new user with administrator privileges.