header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

PHP Director 0.2 Sql Injection

A SQL injection vulnerability exists in PHP Director 0.2. An attacker can send a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the database, modify data, or execute system level commands.

2^6 TCP Control Bit Fuzzer (No ECN or CWR)

This code was written originally as a control bit fuzzer for the JunOS 3-9 crash mentioned in PSN-2010-01-623 and http://www.securityfocus.com/news/11571. It will also be useful in fuzzing future IP stacks, such as userland IP stacks or embedded systems. It was going to be the full 2^8, however Net::RawIP does't support the ECE or the CWR bit, so a Metasploit auxillery is in the works to cover the full 2^8.

Joomla Component com_lead SQL Injection

An SQL injection vulnerability exists in the Joomla Component com_lead. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands in the back-end database, allowing them to access or modify sensitive data.

K9 Kreativity Design (pages.php) SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter page_ID. The malicious query can be sent via a GET request to the vulnerable parameter page_ID. The malicious query can be used to extract sensitive information from the database such as usernames, passwords, and user access levels.

Motorola SURFBoard Cable Modem Directory Traversal

The vulnerability allows an attacker to access the /etc/passwd file from the modem by using the following URLs: http://[IP]///etc/passwd, http://[IP]/../../etc/passwd, http://[IP]/..%2f..%2fetc/passwd, http://[IP]/%2e%2e/%2e%2e/etc/passwd.

PHP SETI@home web monitor (phpsetimon) RFI / LFI Vulnerability

The PHP SETI@home web monitor is vulnerable to both Remote File Inclusion (RFI) and Local File Inclusion (LFI) attacks. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This request can contain a malicious file which can be included in the vulnerable script. This malicious file can be used to execute arbitrary code on the vulnerable server.

Advanced Management For Services Sites (File Disclosure) Vulnerabilities

A vulnerability exists in Advanced Management For Services Sites (AM4SS) which allows an attacker to disclose sensitive information such as configuration files. This is done by sending a specially crafted HTTP request to the vulnerable server which contains the path to the configuration file. The vulnerable parameter is ‘do’ which is located in the ‘am4ss/admincp/misc.php/login.php’ file. An example of the exploit is http://[site]/am4ss/admincp/misc.php/login.php?do=/includes/configure.php

Recent Exploits: