header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Joomla com_mysms Upload Vulnerability

MySMS is standing for 'Simple sms component' for Joomla. The MySMS component is now available for Joomla 1.0.x ( com_mysms-0.9.4.zip ) and for Joomla 1.5.x series ( use com_mysms-1.5.10.zip ). This component supports following sms gateway provider today: w2sms, teleword, smskaufen, smscreator, sms77, sms4credits, mobilant, mesmo, clickatell, aspsms, nohnoh, mexado, innosend, suresms,compaya and hardwired, mobilenl, sloono, smsat and wannfind, agiletelecom, smsviainternet, infobip, at&t, smscom, coolsms, smsglobal, aruhat, massenversand, smstrade. The attacker can upload shell in the 'Import phonebook' option and it doesnt validate any file format so upload your shell.

Joomla com_myhome BSQLi Vulnerability

MyHome is a component for Joomla 1.5, for publishing houses within web sites. The visitor can search for a vehicle by setting selection filters in the “Vertical search module” or “Horizontal search module” or by clicking on a specific module by viewing the list of Hot Houses, etc. The list of houses can be grouped by price, contract type or category. The house main image and information are shown within the list of houses. By clicking on the [DETAILS] button for each house, all the information and images related to it will be shown. N.B. An house may have an unlimited number of images. Unlimited fields can be set up for each house. In the component configuration panel it is possible to create or delete any of the fields required for managing your fleet of houses. It is also possible to add fields later. The fields which can be created may be TEXT type or CHECK type. Xploit: BSQLi Vulnerability DEMO URL : http://server/path/index.php?option=com_myhome&task=4&nidimm=[BSQLi]

Joomla Component com_redshop 1.0 (pid) SQL Injection Vulnerability

A vulnerability exists in Joomla Component com_redshop 1.0 (pid) which allows an attacker to inject arbitrary SQL commands. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code in the 'pid' parameter in a vulnerable URL. This can be used to bypass authentication and gain access to unauthorized data or to modify data.

DotDefender <= 3.8-5 No Authentication Remote Code Execution Through XSS

This exploit is a multi-staged attack against DotDefender through the use of ASRF (or as I call it AJAX Site Request Forgery). It begins by exploiting a post-authentication remote-code execution vulnerability discovered by John Dos. This vulnerability is then used to take the attack from post-authentication to a no-authentication attack. The attack is successful due to a lack of proper sanitization of the information presented to the administrator in the HTTP Headers section of the application. The attack is triggered by sending a malicious request to the server, which then allows malicious code to be injected into the HTTP Headers section of the application. This code is then executed by the administrator when they view the event details.

RSP MP3 Player OCX 3.2 ActiveX Buffer Overflow

A buffer overflow vulnerability exists in RSP MP3 Player OCX 3.2 ActiveX control due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by enticing a victim to visit a malicious web page containing a specially crafted VBScript code. This can result in arbitrary code execution in the context of the current user.

HoloCMS 9.0.47 (news.php) SQL Injection Vulnerability

HoloCMS 9.0.47 is vulnerable to a SQL injection vulnerability in the news.php page. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL code to the vulnerable page. This can allow the attacker to gain access to sensitive information stored in the database, such as user credentials and other confidential data.

Joomla Component (com_quickfaq) BSQL-i Vulnerability

QuickFAQ is vulnerable to Blind SQL Injection. This vulnerability allows an attacker to execute arbitrary SQL commands on the vulnerable system. The vulnerability is located in the 'cid' parameter of the 'category' value of the 'view' parameter when making a GET request to the vulnerable application. An attacker can inject malicious SQL commands to manipulate the content of the database.

mshtml.dll CTimeoutEventList::InsertIntoTimeoutList Timer ID Pointer leak – Rubén Santamarta www.reversemode.com

This exploit is based on the mshtml.dll CTimeoutEventList::InsertIntoTimeoutList Timer ID Pointer leak vulnerability. It allows an attacker to leak a pointer by pressing a button and running a setInterval() function. The pointer is then displayed in the 'atun' div element.

Recent Exploits: