header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

ZeeAdbox v2x SQL Injection Vulnerability

OManage Your Advertisers With Complete Ease Using ZeeAdBox v1.1- All-In-One Powerful Banner & Text Ad Solution. Offer a wide range of Advertising spaces on your website. Have your own banner ads/text ads rotating system on your web pages. A demonstration of the vulnerability can be found at http://www.site.com/bannerclick.php?bnnnerid=11

phpBazar admin information discloser Vulnerability

phpBazar is vulnerable to an information discloser vulnerability. This vulnerability allows an attacker to view the admin panel of the website without authentication. This vulnerability is caused due to the improper validation of the ‘action’ parameter in the ‘admin.php’ script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script.

Free PHP photo gallery script Remote File inclusion

A vulnerability exists in the Free PHP photo gallery script, which allows a remote attacker to include a file from a remote location. The vulnerability is due to the 'include_once($path)' function in the '/jadro/libs/adodb/adodb.inc.php' file, which is located at line 4227. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request containing a maliciously crafted 'path' parameter. This will allow the attacker to include a remote file, resulting in arbitrary code execution.

Free PHP photo gallery script Remote Command Execution

A vulnerability exists in the 'exec' function in the 'adodb-perf.inc.php' file of the Free PHP photo gallery script, which can be exploited to execute arbitrary commands. An attacker can send a specially crafted HTTP request containing an executable command to the vulnerable script in order to execute the command on the vulnerable system.

AJ HYIP MERIDIAN (news.php id) Blind SQL Injection Vulnerability

AJ HYIP Meridian is prone to a blind SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

AJ HYIP PRIME (welcome.php id) Blind SQL Injection Vulnerability

AJ HYIP PRIME is vulnerable to Blind SQL Injection. This vulnerability can be exploited by sending a maliciously crafted HTTP request to the vulnerable server. An attacker can use this vulnerability to gain access to sensitive information stored in the database, such as usernames and passwords. The vulnerability is caused by the lack of proper input validation of the 'id' parameter in the 'welcome.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL code to the vulnerable server. The malicious code will be executed in the context of the web server, allowing the attacker to gain access to sensitive information stored in the database.

Joomla Component com_jomtube (user_id) Blind SQL Injection / SQL Injection

A vulnerability exists in Joomla Component com_jomtube (user_id) which allows an attacker to inject arbitrary SQL commands. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can result in the disclosure of sensitive information from the database.

OpenX (phpAdsNew) Remote File inclusion Vulnerability

OpenX (phpAdsNew) is vulnerable to a remote file inclusion vulnerability. This vulnerability is caused due to the use of user-supplied input without proper validation. A remote attacker can exploit this vulnerability to include a remote file containing malicious code and execute it in the context of the webserver process.

Recent Exploits: