header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

iFdate Social Dating Script v2.0 – SQL Injection

Multiple parameters in the iFdate Social Dating Script v2.0 are vulnerable to SQL injection, allowing an attacker to extract data from the database. The vulnerable parameters are gender, sexuality, marital, ethnic, country, picture, online, error_name, username, and videos. The data that can be extracted includes id, username, email, password, signup_date, signup_ip, banned, active, and is_admin.

Pasal – Departmental Store Management System v1.2 – SQL Injection

Pasal - Departmental Store Management System v1.2 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain access to sensitive information such as usernames, passwords, emails, full names, and permissions from the tbl_users table. The vulnerable parameters are module.php?module=vendors&page=edit-vendors&id=[SQL], module.php?module=units&page=edit-units&id=[SQL], module.php?module=currency&page=edit-currency&id=[SQL], module.php?module=category&page=edit-category&id=[SQL], and module.php?module=purchase&y=[SQL]&m=[SQL].

ImagePath Resource Injection/Open script editor

The variable 'imagePath=' (that is prone to XSS in a large range of products) also can be used to resource injection intents. If inserted a URL in this variable will be made an GET request to this URL, so this an interesting point to request malicious codes from the attacker machine, and of course, the possibilities are vast (including hook the browser).

WordPress Plugin Membership Simplified v1.58 – Arbitrary File Download

This exploit allows an attacker to download arbitrary files from a vulnerable Wordpress Plugin Membership Simplified v1.58 installation. The attacker can specify the file to download by manipulating the download_file parameter in the download.php file.

Stored Cross Site Scripting (XSS) in Sitecore Experience Platform 8.1 Update-3

Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted web sites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Name and Description input fields aren't properly escaped. This could lead to an XSS attack that could possibly affect administrators,users,editor.

IPS Community Suite – Steam Profile Integration 2.0.11 and below SQL injection

An unauthenticated attacker can inject arbitrary SQL commands into the 'id' parameter of the 'update' action of the 'steamProfile' module of the IPS Community Suite. This is due to the lack of proper sanitization of the 'id' parameter in the 'updateProfile()' function of the 'Update.php' file. This can allow an attacker to gain access to sensitive information from the database.

Recent Exploits: