A SQL injection vulnerability exists in Multireligion Responsive Matrimonial Script v4.7.1, which allows an attacker to inject malicious SQL code into the 'search-smart-result.php' script via the 'cityse', 'gender', 'subcaste', 'diet', 'smoke', 'drink', 'body_type', 'familyvalue', 'familystatus' and 'asubmit' parameters.
A SQL injection vulnerability exists in MLM Membership Plan Script v2.0.5. An attacker can send malicious SQL queries to the vulnerable parameter 'newid' and 'eventid' in 'news_detail.php' and 'event_detail.php' respectively, which can be used to extract sensitive information from the database. An attacker can also use the 'export_set' function to extract the admin credentials from the 'mlm_admin' table.
A SQL injection vulnerability exists in MLM Forex Market Plan Script v2.0.1. An attacker can send a specially crafted SQL query to the vulnerable parameter 'newid' and 'eventid' in 'news_detail.php' and 'event_detail.php' scripts respectively, which will allow the attacker to extract sensitive information from the database.
An SQL injection vulnerability exists in MLM Forced Matrix v2.0.7, which allows an attacker to execute arbitrary SQL commands via the 'newid' and 'eventid' parameters in the 'news_detail.php' and 'event_detail.php' scripts. An attacker can use this vulnerability to gain access to the admin panel and extract sensitive information such as usernames and passwords from the 'mlm_admin' table.
An SQL injection vulnerability exists in MLM Binary Plan Script v2.0.5. An attacker can send a specially crafted HTTP request to the vulnerable application in order to execute arbitrary SQL commands in the back-end database. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code in the affected parameter. This can be used to bypass authentication and gain access to the application.
Matrimonial Script v3.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the application. This can be done by manipulating the 'mother_tongue_search.php' and 'index_search_result.php' parameters. An attacker can also use the 'adminlogin' table to extract user credentials.
Entrepreneur B2B Script v2.0.4 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain access to sensitive information such as usernames and passwords stored in the database. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'id' parameter of the 'news-details.php' script. An attacker can send a malicious SQL query to the vulnerable script in order to gain access to the sensitive information stored in the database.
An attacker can exploit a SQL injection vulnerability in PHP Classifieds Rental Script v3.6.0 to gain access to sensitive information such as usernames and passwords. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'viewsubproducts.php' script. An attacker can send a specially crafted HTTP request containing malicious SQL statements to the vulnerable script and execute arbitrary SQL commands in application's database.
An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameters of the application. For example, an attacker can send -1'+/*!50000union*/+select+1,2,3,4,@@version,6-- -, -1'+/*!50000union*/+select+1,2,3,4,5,@@version,7,8,9-- -, -1'+/*!50000union*/+select+1,2,3,4,5,6,@@version,8-- -, etc. to the vulnerable parameters of the application.
Advanced Matrimonial Script v2.0.3 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameters of the application. This can allow an attacker to gain access to sensitive information such as usernames and passwords stored in the database.