header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Cross-site scripting vulnerability in CedStat

CedStat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Cross-Site Scripting Vulnerability in Google Desktop

The Google Desktop application fails to properly sanitize user-supplied input, leading to a cross-site scripting vulnerability. Attackers can exploit this vulnerability in conjunction with a latent cross-site scripting vulnerability in the 'google.com' domain to execute arbitrary script code in the browser of an unsuspecting user. This can allow attackers to access the contents of the Google Desktop search index or potentially execute arbitrary code.

Userpages2 SQL Injection Vulnerability

Userpages2 is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Cross-site scripting vulnerabilities in MyCalendar

The MyCalendar application is vulnerable to multiple cross-site scripting vulnerabilities due to inadequate sanitization of user-supplied input. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of a victim user, within the context of the affected site. This can lead to the theft of authentication credentials and enable the attacker to launch further attacks.

Remote Stack-based Buffer Overflow Vulnerability in News File Grabber

News File Grabber is prone to a remote stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. Exploiting this issue allows attackers to execute arbitrary machine code in the context of the affected application.

Apple iTunes Remote Denial-of-Service Vulnerability

The vulnerability exists because the application does not properly handle malformed XML playlist files. An attacker can exploit this issue by crafting a malicious playlist file and tricking the user into opening it, causing the application to crash and resulting in a denial-of-service condition.

Recent Exploits: