header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Joomla com_autartimonial Sqli Vulnerability

AutarTimonial consists of a component to manage testimonials, and a module displaying randomly a testimonial. This component has multilingual support. English and French are currently available. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable parameter 'limit' in the URL.

Multi-Vendor Shopping Malls SQL Injection Vulnerability

A complete application for Multi-Vendor Shopping Malls with online built-in order placement and processing system, Buying and Selling options, Submit your bulk requirements. Unlimited Store owners can add their stores and products to this system to sale and market their products on single platform. Website owner can add unlimited categories and sub-categories to this E-Commerce system. Store owners have private control panel and order management system. Highly advance new design features with easy template customizations. Major payment gateways included with complete control from admin section. Highly secure customer and store own registrations. Search product by your choice and favorite Store. The world best Multi-Vendor E-Commerce online solution. An attacker can exploit this vulnerability by injecting malicious SQL queries into the vulnerable parameter of the application. This can allow the attacker to gain unauthorized access to the application and its data.

Lyrics V3 engine Sqli Vulnerability

A SQL injection vulnerability was discovered in the Lyrics V3 engine. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This request contains a specially crafted SQL query which can be used to extract sensitive information from the database.

BS Classifieds Ads

The vulnerability exists due to insufficient filtration of user-supplied data passed via the 'id' parameter to the '/General_Classifieds/articlesdetails.php' script. A remote attacker can send a specially crafted request to the vulnerable script and execute arbitrary SQL commands in the application's database. This can be exploited to disclose the application's data, including the administrator's credentials stored in the 'fpoll_config' table.

Auto Dealer <= SQL Injection Vulnerability Proof of Concept

A SQL injection vulnerability was discovered in the BS Auto Dealer script, which allows an attacker to execute arbitrary SQL commands on the underlying database. The vulnerability exists in the info.php page, which is vulnerable to a UNION-based SQL injection attack. The attack can be used to extract data from the cars_agents table, including the LastName, FirstName, password, username, AgentID, and email fields.

IBM Bladecenter Management – Multiple vulnerabilities

The BladeCenter management module is prone to multiple security vulnerabilities: Unauthorized Access, Directory Listing, XSS. Multiple XSS vulnerabilities were found in bladecenter web management, a Directory Listing vulnerability was found in bladecenter web management, and unauthorized access to sensitive data (system logs, cores) can be done by requesting a file. All three issues were fixed in the latest version of the BladeCenter management module.

Recent Exploits: