header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Joomla Component Sponsor Wall 7.0 – SQL Injection

The wallid parameter of the Joomla Component Sponsor Wall 7.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a malicious SQL query to the wallid parameter of the application. This can allow the attacker to gain access to sensitive information stored in the database.

Cimetrics BACstac Routing Service 6.2f Local Privilege Escalation

The application suffers from an unquoted search path issue impacting the service 'bacstac' (bacstac-gtw.exe) for Windows deployed as part of BACstac routing service solution. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user’s code would execute with the elevated privileges of the application.

Quadz School Management System v3.1 – SQL Injection

Login as student user and inject malicious SQL code in the URL parameters 'uisd' of the following URLs: http://localhost/[PATH]/index.php/sclass/ownClassRoutin?uisd=[SQL] and http://localhost/[PATH]/index.php/suggestion/own_suggestion?uisd=[SQL]

Viavi Product Review – SQL Injection

An attacker can exploit a SQL injection vulnerability in the Viavi Product Review application to execute arbitrary SQL commands on the underlying database. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'id' parameter of the 'category.php' script.

Recent Exploits: