header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

CVE-2017-6552 – Local DoS Buffer Overflow Livebox 3

Livebox router has its default IPv6 routing table max. size too small and therefore can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting in a denial-of-service condition for Phone, Internet and TV services.

TradeMart – B2B Trading Software v1.1 – SQL Injection

An attacker can exploit a SQL injection vulnerability in TradeMart - B2B Trading Software v1.1 by sending a maliciously crafted HTTP request to the application. The application is vulnerable to a SQL injection attack when the 'by' and 'q' parameters are not properly sanitized before being used in a SQL query. An attacker can exploit this vulnerability to gain access to sensitive information from the database.

Fashmark – eCommerce Script v1.2 – SQL Injection

A SQL injection vulnerability exists in Fashmark - eCommerce Script v1.2. An attacker can send a malicious SQL query to the search parameter of the application in order to execute arbitrary SQL commands in the back-end database. This can be exploited to manipulate SQL queries to view, add, modify and delete records in the back-end database.

Nlance – Freelance Marketplace Software v2.2 – SQL Injection

Nlance - Freelance Marketplace Software v2.2 is vulnerable to SQL Injection. An attacker can inject malicious SQL queries via the 'skill' parameter in the 'search/provider/' page. For example, http://localhost/[PATH]/search/provider/?skill=[SQL] -38'+/*!50000union*/+select+1,@@version--+- can be used to inject malicious SQL queries.

BistroStays – Vacation Rental Software v3.0 – SQL Injection

An attacker can exploit a SQL injection vulnerability in BistroStays - Vacation Rental Software v3.0 to execute arbitrary SQL commands on the underlying database. This can be done by sending maliciously crafted input to the application, which is then passed to the database server for execution. This can be done by sending maliciously crafted input to the application, which is then passed to the database server for execution.

Media Search Engine Script – SQL Injection

An attacker can exploit a SQL injection vulnerability in Media Search Engine Script to gain unauthorized access to the application and its data. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'search' parameter of the 'search.php' script. An attacker can send malicious SQL queries to the application, which can be used to access or modify the application's data, or even gain access to the underlying system.

Country on Sale Script – SQL Injection

Country on Sale Script is vulnerable to SQL Injection. Attackers can exploit this vulnerability to gain access to sensitive information stored in the database. The vulnerable parameters are 'newsid' and 'id' in the 'read_more.php' and 'index.php' files respectively. An example of the exploit is '13'+/*!50000union*/+select+1,version(),0x496873616e2053656e63616e3c62723e7777772e696873616e2e6e6574,4,5--+-'

Recent Exploits: