A SQL injection vulnerability exists in PHP Director 0.2. An attacker can send a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the database, modify data, or execute system level commands.
The 'skin' parameter in FILE thanks.php is not Defined which can allow remote attacker to include remote file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'skin' parameter.
This exploit is for OS X EvoCam Web Server versions 3.6.6 and 3.6.7. It is a buffer overflow exploit which sends an evil buffer to the target host and port. The payload contains a shellcode which executes /bin/sh on the target machine.
This code was written originally as a control bit fuzzer for the JunOS 3-9 crash mentioned in PSN-2010-01-623 and http://www.securityfocus.com/news/11571. It will also be useful in fuzzing future IP stacks, such as userland IP stacks or embedded systems. It was going to be the full 2^8, however Net::RawIP does't support the ECE or the CWR bit, so a Metasploit auxillery is in the works to cover the full 2^8.
An SQL injection vulnerability exists in the Joomla Component com_lead. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary SQL commands in the back-end database, allowing them to access or modify sensitive data.
The vulnerability exists in the 'qui_som.php', 'eobre_grupo_lleal.php' and 'galeria.php' files of the clickartweb website, where an attacker can inject malicious SQL code into the 'id' parameter of the URL.
An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter page_ID. The malicious query can be sent via a GET request to the vulnerable parameter page_ID. The malicious query can be used to extract sensitive information from the database such as usernames, passwords, and user access levels.
The vulnerability allows an attacker to access the /etc/passwd file from the modem by using the following URLs: http://[IP]///etc/passwd, http://[IP]/../../etc/passwd, http://[IP]/..%2f..%2fetc/passwd, http://[IP]/%2e%2e/%2e%2e/etc/passwd.
The PHP SETI@home web monitor is vulnerable to both Remote File Inclusion (RFI) and Local File Inclusion (LFI) attacks. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This request can contain a malicious file which can be included in the vulnerable script. This malicious file can be used to execute arbitrary code on the vulnerable server.
A vulnerability exists in Advanced Management For Services Sites (AM4SS) which allows an attacker to disclose sensitive information such as configuration files. This is done by sending a specially crafted HTTP request to the vulnerable server which contains the path to the configuration file. The vulnerable parameter is ‘do’ which is located in the ‘am4ss/admincp/misc.php/login.php’ file. An example of the exploit is http://[site]/am4ss/admincp/misc.php/login.php?do=/includes/configure.php