Livebox router has its default IPv6 routing table max. size too small and therefore can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting in a denial-of-service condition for Phone, Internet and TV services.
An attacker can exploit a SQL injection vulnerability in TradeMart - B2B Trading Software v1.1 by sending a maliciously crafted HTTP request to the application. The application is vulnerable to a SQL injection attack when the 'by' and 'q' parameters are not properly sanitized before being used in a SQL query. An attacker can exploit this vulnerability to gain access to sensitive information from the database.
A SQL injection vulnerability exists in Fashmark - eCommerce Script v1.2. An attacker can send a malicious SQL query to the search parameter of the application in order to execute arbitrary SQL commands in the back-end database. This can be exploited to manipulate SQL queries to view, add, modify and delete records in the back-end database.
An attacker can exploit a SQL injection vulnerability in Busewe - Website Marketplace Software v1.2 to gain access to admin credentials such as id, username, password, masterPassword, email, role and permissions.
Nlance - Freelance Marketplace Software v2.2 is vulnerable to SQL Injection. An attacker can inject malicious SQL queries via the 'skill' parameter in the 'search/provider/' page. For example, http://localhost/[PATH]/search/provider/?skill=[SQL] -38'+/*!50000union*/+select+1,@@version--+- can be used to inject malicious SQL queries.
An attacker can exploit a SQL injection vulnerability in BistroStays - Vacation Rental Software v3.0 to execute arbitrary SQL commands on the underlying database. This can be done by sending maliciously crafted input to the application, which is then passed to the database server for execution. This can be done by sending maliciously crafted input to the application, which is then passed to the database server for execution.
Soundify is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain access to sensitive information such as adminId, firstName, userName, adminEmail, passWord, adminType, etc. from the database.
An attacker can exploit a SQL injection vulnerability in Media Search Engine Script to gain unauthorized access to the application and its data. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'search' parameter of the 'search.php' script. An attacker can send malicious SQL queries to the application, which can be used to access or modify the application's data, or even gain access to the underlying system.
Country on Sale Script is vulnerable to SQL Injection. Attackers can exploit this vulnerability to gain access to sensitive information stored in the database. The vulnerable parameters are 'newsid' and 'id' in the 'read_more.php' and 'index.php' files respectively. An example of the exploit is '13'+/*!50000union*/+select+1,version(),0x496873616e2053656e63616e3c62723e7777772e696873616e2e6e6574,4,5--+-'
A SQL injection vulnerability exists in Envato Clone Script, which allows an attacker to execute arbitrary SQL commands via the 'by' parameter in the 'codes/php-scripts/', 'graphics/graphics/', 'themes/word-press/', and 'audios/music/' scripts.