header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Remote code execution via CSRF vulnerability in the web UI of Deluge 1.3.13

Deluge version 1.3.13 is vulnerable to cross-site request forgery in the Web UI plug-in resulting in remote code execution. Requests made to the /json endpoint are not checked for CSRF. A malicious web page can use forged requests to make Deluge download and install a Deluge plug-in provided by the attacker. The plug-in can then execute arbitrary code as the user running Deluge (usually the local user account).

Multiple WordPress Plugin – Remote File Upload Exploit

Multiple Wordpress plugins are vulnerable to a remote file upload vulnerability. This vulnerability allows an attacker to upload a malicious file to the vulnerable server. The vulnerable plugins are Zen App Mobile Native <=3.0 (CVE-2017-6104), Wordpress Plugin webapp-builder v2.0 (CVE-2017-1002002), Wordpress Plugin wp2android-turn-wp-site-into-android-app v1.1.4 (CVE-2017-1002003), Wordpress Plugin mobile-app-builder-by-wappress v1.05 (CVE-2017-1002001), and Wordpress Plugin mobile-friendly-app-builder-by-easytouch v3.0 (CVE-2017-1002000).

Website Broker Script v3.02 – SQL Injection

An SQL injection vulnerability exists in Website Broker Script v3.02, which allows an attacker to execute arbitrary SQL commands via the 'view' parameter in 'website_details_view.php'. An attacker can use this vulnerability to gain access to sensitive information such as usernames and passwords from the database.

Social Network Script v3.01 – SQL Injection

An attacker can exploit SQL injection vulnerability in Social Network Script v3.01 by sending malicious SQL queries to the application. This can be done by manipulating the 'id' parameter in the following URLs: http://localhost/[PATH]/[SQL], http://localhost/scrapbook.php?id=[SQL], http://localhost/profile_social.php?id=[SQL], http://localhost/my_bookmark.php?id=[SQL], http://localhost/profile_social.php?mode=addbookmark&id=[SQL], etc.

Select Your College Script v2.01 – SQL Injection

The vulnerability exists in the Select Your College Script v2.01, which allows an attacker to inject malicious SQL queries via the 'institute', 'namesearch', 'name', 'categoryid', and 'id' parameters in the 'searchresult.php', 'searchcourse.php', and 'collegedetails.php' scripts.

Schools Alert Management Script v2.01 – SQL Injection

An unauthenticated attacker can exploit a SQL injection vulnerability in Schools Alert Management Script v2.01. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'list_id' parameter of the 'view_school_list.php' script. An attacker can exploit this vulnerability to gain access to sensitive information from the database, such as usernames and passwords. The attacker can also execute arbitrary SQL queries in the back-end database.

Responsive Matrimonial Script v4.0.1 – SQL Injection

A SQL injection vulnerability exists in Responsive Matrimonial Script v4.0.1. An attacker can send malicious SQL queries to the application which can be used to access or modify the application's data. The vulnerability is due to the application not properly sanitizing user-supplied input before using it in an SQL query. An attacker can exploit this vulnerability to gain access to unauthorized data or to modify existing data within the application's database.

PHP B2B Script v3.05 – SQL Injection

A SQL injection vulnerability exists in PHP B2B Script v3.05, which allows an attacker to execute arbitrary SQL commands via the 'id', 'bid' and 'id' parameters in the 'companyinfo.php', 'latest_selling_leads_details.php' and 'company_profile.php' scripts, respectively. An attacker can use this vulnerability to gain access to the admin panel and extract sensitive information from the database.

Network Community Script v3.0.2 – SQL Injection

Network Community Script v3.0.2 is vulnerable to SQL Injection. An attacker can inject malicious SQL queries via the 'jview' parameter in the 'refer_job_view.php' script. This can be exploited to gain access to the admin panel and extract sensitive information from the database.

Recent Exploits: