header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Hotel Booking Portal v0.1 Multiple Vulnerabilities

A vulnerability exists in 'login.php' - Allows for 'SQL injection' of the 'email' and 'password' POST parameters. A vulnerability exists in 'searchresults.php' - Allows for 'SQL injection' of the 'country' POST parameter. A vulnerability exists in 'includes/languagebar.php' - Allows for 'Cross site scripting' of the 'window.location' js. A vulnerability exists in 'administrator/login.php' - Allows for 'Cross site scripting' of the 'window.location' js. A vulnerability exists in 'index.php' - Allows for 'Cross site scripting' of the 'lang' GET parameter.

NetVizor Client DoS

NetVizor is the latest in network monitoring software. It is possible to have the service crash by sending an overly large string. This will will overwrite EAX or ECX and the “Viewer” application will no longer be able to initiate a remote desktop connection nor will it be able to grab a screen capture.

MobileCartly 1.0 Arbitrary File Write Vulnerability

The application is prone to arbitrary file write / overwrite vulnerability. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The request should contain the filename and the code to be written in the file. For example, an attacker can send a request with the filename 'shell.php' and the code '<?php echo(shell_exec($_GET['cmd'])); ?>' to write a malicious file in the application directory. This malicious file can then be used to execute arbitrary commands on the server.

ProQuiz v2.0.2 – Multiple Vulnerabilities

ProQuiz v2.0.2 is vulnerable to Remote File Include, Local File Include, Remote SQL Injection & Blind SQL Injection. In File (my_account.php) in line 114 & 115, if($_GET['action']=='getpage' && !empty($_GET['page'])){@include_once($_GET['page'].'.php'); is vulnerable to Remote File Include & Local File Include. For Remote File Include, an attacker can register and login in the panel and paste the malicious URL. For Local File Include, an attacker can register and login in the panel and paste the malicious URL. For Remote SQL Injection & Blind SQL Injection, in two files, answers.php in line 55 and functions.php in $_POST['email'] and $_POST['username'], an attacker can inject malicious SQL code in the URL and POST method.

Flynax General Classifieds v4.0 CMS – Multiple Vulnerabilities

The Vulnerability Laboratory Research Team discovered multiple Web Vulnerabilities in the Flynax General Classifieds v4.0 CMS. A SQL Injection vulnerability is detected in the Flynax General Classifieds v4.0 Content Management System. Remote attackers without privileged user accounts can execute/inject own sql commands to compromise the application dbms. The vulnerability is located in the general module with the bound vulnerable sort_by parameter. Multiple persistent input validation vulnerabilities are detected in the Flynax General Classifieds v4.0 Content Management System. Remote attackers can inject own malicious script codes to compromise the application or session of the remote user. The vulnerabilities are located in the general module with the bound vulnerable search_by & search_for parameters. A persistent Cross Site Scripting vulnerability is detected in the Flynax General Classifieds v4.0 Content Management System. Remote attackers can inject own malicious script codes to compromise the application or session of the remote user. The vulnerability is located in the general module with the bound vulnerable search_by & search_for parameters.

Solaris 10 Patch 137097-01 Local Privilege-Escalation Vulnerability

Solaris 10 Patch 137097-01 is prone to a local privilege-escalation vulnerability. Local attackers can exploit this issue to gain elevated privileges on affected computers. The exploit code creates a symlink from /etc/passwd to /tmp/iconf_entries.PID, where PID is the process ID of the inetd-upgrade process.

WordPress Mz-jajak plugin <= 2.1 SQL Injection Vulnerability

A SQL injection vulnerability exists in the WordPress Mz-jajak plugin version 2.1 and below. An attacker can send a specially crafted POST request to the index.php page with malicious SQL code in the 'id' parameter. This can allow the attacker to gain access to sensitive information from the database.

Recent Exploits: