header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Joomla! Component AltaUserPoints v1.1 – SQL Injection

A SQL injection vulnerability exists in Joomla! Component AltaUserPoints v1.1. An attacker can exploit this vulnerability by sending a specially crafted SQL query to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the database.

Joomla! Component Content ConstructionKit v1.1 – SQL Injection

A SQL injection vulnerability exists in Joomla! Component Content ConstructionKit v1.1. An attacker can send a specially crafted HTTP request to the vulnerable application in order to execute arbitrary SQL commands in the back-end database. This can result in the manipulation or disclosure of arbitrary data in the back-end database.

Joomla! Component AYS Quiz v1.0 – SQL Injection

Joomla! Component AYS Quiz v1.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a specially crafted SQL query to the vulnerable application. This can be done by sending a malicious SQL query to the vulnerable parameter ‘id’ in the ‘index.php’ page. An attacker can use this vulnerability to gain access to the database and extract sensitive information such as usernames and passwords.

Joomla! Component Monthly Archive v3.6.4 – SQL Injection

An attacker can exploit a SQL injection vulnerability in Joomla! Component Monthly Archive v3.6.4 by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can allow the attacker to gain access to sensitive information from the database, modify data, or execute arbitrary system commands.

Joomla! Component JUX EventOn v1.0.1 – SQL Injection

An attacker can exploit a SQL injection vulnerability in Joomla! Component JUX EventOn v1.0.1 to execute arbitrary SQL commands by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can be done by appending malicious SQL statements to the vulnerable parameter in the HTTP request.

pfSense 2.3.2 XSS – CSRF-bypass & Reverse-root-shell

There are several RXSS in GET parameter available on the pfSense WebGui, example : File status_captiveportal.php GET parameter : zone http://[IP]/status_captiveportal.php?zone=<script>alert(1)</script> The CSRF security mechanism can be bypassed by using the RXSS vulnerability. The RXSS vulnerability can be used to trigger a reverse root shell.

Joomla! Component Coupon v3.5 – SQL Injection

A SQL Injection vulnerability exists in Joomla! Component Coupon v3.5, which allows an attacker to inject malicious SQL code into the application. The vulnerable parameters are 'option=com_coupon&view=coupons&task=mail_box&', 'option=com_coupon&view=coupons&catid' and 'option=com_coupon&view=coupons&storeid'. An example of the exploit is provided in the text.

WordPress REST API Information Disclosure Vulnerability

WordPress Core before 4.7.1 is susceptible to user enumeration because it does not properly restrict listings of post authors via wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API, which allows a remote attacker to obtain sensitive information via a wp-json/wp/v2/users request.

Recent Exploits: