header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Bs Scripts_Directory Sqli/Auth Bypass Vulnerability

BS Scripts Directory software allows users to browse and search for scripts. The listings are fully detailed with photos, features, descriptions, ratings, reviews, and seller's information. Members can also post their scripts in the categories added by administrator. After the registration user is able to select and buy a advertising package depending on the length of time he/she would like their listings to be displayed on the website. Payment can be made through PayPal or 2Checkout. The user will be informed automatically about his statistics - 10 days before the expiration of his account , 5 days, 1 day. 24 hours after his account expiration date, all his listings and his account will be deleted automatically from the system. The SQL Injection vulnerability can be exploited by appending a malicious SQL query to the 's' parameter in the 'search.php' script. The Authentication Bypass vulnerability can be exploited by using ' or 1=1 or ''=' in both username and password fields.

Version: v0.28 (Possible all versions)

In the file named as getpage.php user input don't used in single quotes. Its successfully exploitable. Request: http://server/handlers/getpage.php?id=9999999+UNION+SELECT+1,CONCAT_WS(0x3a,user_name,password),3,4,5,6,7+FROM+user+LIMIT+1 Response: admin:21232f297a57a5a743894a0e4a801fc3

SasCam 2.7 ActiveX Head Buffer Overflow

This exploit is a buffer overflow vulnerability in the SasCam 2.7 ActiveX control. It is triggered when a maliciously crafted HEAD request is sent to the vulnerable control. This causes a stack-based buffer overflow, which allows an attacker to execute arbitrary code on the target system.

bbPress v 1.0.2 CSRF

This exploit allows an attacker to change the display name, email address, and role of a user in bbPress v 1.0.2. The attacker can craft a malicious HTML page that contains a form with hidden fields that contain the new values for the user. When the victim visits the malicious page, the form is automatically submitted and the user's information is changed.

Joomla Component SEF (com_sef) – LFI Vulnerability

Joomla Component SEF (com_sef) is vulnerable to Local File Inclusion (LFI) vulnerability. The vulnerable parameters are 'view' and 'controller'. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. The malicious request can be in the form of 'http://<server>/index.php?option=com_sef&controller=../../../../../../../../../../../../../../../etc/passwd%00'

Joomla com_ninjamonials BSqli Vulnerability

NinjaMonials is designed to help you quickly and easily collect and display testimonials for your site. Testimonials improve customer confidence, which in turn improves the ability of your site to convert visitors into customers and members. Any internet marketing expert will tell you that testimonials will improve the conversion rates of guests into members on virtually any site. By providing guests with 3rd party, honest reviews from customers they get a much more solid idea of how your site and service really is, and are not required to believe only your marketing material.

Joomla com_addressbook Blind Sqli Vulnerability

The Front-edit Address Book is a powerful, but easy to use address book component for Joomla. If a malicious user is able to inject a SQL query into the vulnerable parameter, they can gain access to the underlying database and potentially gain access to sensitive information.

Joomla Front-End Article Manager System Upload Vulnerability

The Front-end article manager system is a simple and very powerful extention, that allows users to manage articles directly from front-end. A vulnerability exists in the system which allows an attacker to upload a malicious file to the server, allowing them to execute arbitrary code on the server.

SQL-i Vulnerability

Phoca Gallery is a Joomla! gallery - image gallery for Joomla! CMS. It includes component, modules and plugins and allows users to display images or Youtube videos in many different styles. An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter 'Itemid' in the URL http://server/path/index.php?option=com_phocagallery&view=categories&Itemid=[SQL Injection].

Esoftpro Online Contact Manager Multiple Vulnerability

Online Contact Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this issue to manipulate SQL queries and gain access to unauthorized information.

Recent Exploits: