A SQL injection vulnerability exists in Joomla! Component AltaUserPoints v1.1. An attacker can exploit this vulnerability by sending a specially crafted SQL query to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the database.
A SQL injection vulnerability exists in Joomla! Component Content ConstructionKit v1.1. An attacker can send a specially crafted HTTP request to the vulnerable application in order to execute arbitrary SQL commands in the back-end database. This can result in the manipulation or disclosure of arbitrary data in the back-end database.
Joomla! Component AYS Quiz v1.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a specially crafted SQL query to the vulnerable application. This can be done by sending a malicious SQL query to the vulnerable parameter ‘id’ in the ‘index.php’ page. An attacker can use this vulnerability to gain access to the database and extract sensitive information such as usernames and passwords.
An attacker can exploit a SQL injection vulnerability in Joomla! Component Monthly Archive v3.6.4 by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can allow the attacker to gain access to sensitive information from the database, modify data, or execute arbitrary system commands.
An attacker can exploit a SQL injection vulnerability in Joomla! Component JUX EventOn v1.0.1 to execute arbitrary SQL commands by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can be done by appending malicious SQL statements to the vulnerable parameter in the HTTP request.
Persistent cross-site scripting (XSS) in the web interface of Epson's TMNet WebConfig Ver 1.00 application allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter.
There are several RXSS in GET parameter available on the pfSense WebGui, example : File status_captiveportal.php GET parameter : zone http://[IP]/status_captiveportal.php?zone=<script>alert(1)</script> The CSRF security mechanism can be bypassed by using the RXSS vulnerability. The RXSS vulnerability can be used to trigger a reverse root shell.
A SQL Injection vulnerability exists in Joomla! Component Coupon v3.5, which allows an attacker to inject malicious SQL code into the application. The vulnerable parameters are 'option=com_coupon&view=coupons&task=mail_box&', 'option=com_coupon&view=coupons&catid' and 'option=com_coupon&view=coupons&storeid'. An example of the exploit is provided in the text.
Command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application.
WordPress Core before 4.7.1 is susceptible to user enumeration because it does not properly restrict listings of post authors via wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API, which allows a remote attacker to obtain sensitive information via a wp-json/wp/v2/users request.