OManage Your Advertisers With Complete Ease Using ZeeAdBox v1.1- All-In-One Powerful Banner & Text Ad Solution. Offer a wide range of Advertising spaces on your website. Have your own banner ads/text ads rotating system on your web pages. A demonstration of the vulnerability can be found at http://www.site.com/bannerclick.php?bnnnerid=11
After find plugin at sites run SQL Inject : example : http://site.com/myLDlinker.php?url=18[SQLi]
A vulnerability in PHPBB MOD [2.0.19] Invitation Only allows an attacker to bypass the passcode or invitation code by entering a quote character ' in the passcode field and clicking submit. This will allow the attacker to access the registration form.
phpBazar is vulnerable to an information discloser vulnerability. This vulnerability allows an attacker to view the admin panel of the website without authentication. This vulnerability is caused due to the improper validation of the ‘action’ parameter in the ‘admin.php’ script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script.
A vulnerability exists in the Free PHP photo gallery script, which allows a remote attacker to include a file from a remote location. The vulnerability is due to the 'include_once($path)' function in the '/jadro/libs/adodb/adodb.inc.php' file, which is located at line 4227. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request containing a maliciously crafted 'path' parameter. This will allow the attacker to include a remote file, resulting in arbitrary code execution.
A vulnerability exists in the 'exec' function in the 'adodb-perf.inc.php' file of the Free PHP photo gallery script, which can be exploited to execute arbitrary commands. An attacker can send a specially crafted HTTP request containing an executable command to the vulnerable script in order to execute the command on the vulnerable system.
AJ HYIP Meridian is prone to a blind SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
AJ HYIP PRIME is vulnerable to Blind SQL Injection. This vulnerability can be exploited by sending a maliciously crafted HTTP request to the vulnerable server. An attacker can use this vulnerability to gain access to sensitive information stored in the database, such as usernames and passwords. The vulnerability is caused by the lack of proper input validation of the 'id' parameter in the 'welcome.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL code to the vulnerable server. The malicious code will be executed in the context of the web server, allowing the attacker to gain access to sensitive information stored in the database.
A vulnerability exists in Joomla Component com_jomtube (user_id) which allows an attacker to inject arbitrary SQL commands. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can result in the disclosure of sensitive information from the database.
OpenX (phpAdsNew) is vulnerable to a remote file inclusion vulnerability. This vulnerability is caused due to the use of user-supplied input without proper validation. A remote attacker can exploit this vulnerability to include a remote file containing malicious code and execute it in the context of the webserver process.