header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Persistent Cross-Site Scripting in the WordPress NewStatPress Plugin

A persistent Cross-Site Scripting (XSS) vulnerability has been found in the WordPress NewStatPress plugin. By using this vulnerability an attacker can inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content.

Popup by Supsystic WordPress Plugin Vulnerable to Cross-Site Request Forgery

A Cross-site Request Forgery vulnerablity exists in the Popup by Supsystic WordPress Plugin. This vulnerablity allows attackers to add and modify scripting code that will target authenticated WordPress admins or visitors that see the popup generated by this plugin. Before exploitation of this issue succeeds, and scripting code is therefore injected, a victim WordPress admin to click a specially crafted link or visit a malicious attacker-controlled webpage.

Cross-Site Request Forgery and Cross-Site Scripting in Contact Form Manager WordPress Plugin

It was discovered that Contact Form Manager does not protect against Cross-Site Request Forgery. This allows an attacker to change arbitrary Contact Form Manager settings. In addtion, the plugin also fails to apply proper output encoding, rendering it vulnerable to stored Cross-Site Scripting. The username input field on the XYZ Contact > SMTP Settings is vulnerabile to stored Cross-Site Scripting.

Synchronet BBS 3.16c for Windows – Multiple vulnerabilities

A vulnerability in Synchronet BBS 3.16c for Windows allows an attacker to cause a denial of service (DoS) condition by sending a specially crafted HTTP request. The vulnerability is due to improper handling of certain HTTP requests. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. Successful exploitation of this vulnerability could result in a DoS condition.

Joomla! Component OneVote! v1.0 – SQL Injection

A SQL injection vulnerability exists in Joomla! Component OneVote! v1.0, which allows an attacker to execute arbitrary SQL commands via the 'election_id' parameter in the 'results.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application.

Recent Exploits: