This exploit is a Denial of Service (DoS) vulnerability in Webkit (Safari) which can be triggered by a maliciously crafted web page. The exploit causes a stack exhaustion in the browser, resulting in a crash.
Acart is a shopping cart software that is vulnerable to a backup dump vulnerability. An attacker can access the acart.mdb and signin.asp files to gain access to the information stored in the database. The vulnerability affects version 2.0 of the software.
An SQL injection vulnerability exists in CLScript.com Classifieds Software, which allows an attacker to execute arbitrary SQL commands via the 'hpId' parameter in the 'help-details.php' script.
A buffer overflow vulnerability exists in Acoustica cd/dvd label maker version 3.32. An attacker can exploit this vulnerability by creating a malicious .m3u file containing 300 A characters, which can cause a buffer overflow and allow arbitrary code execution.
Help Center Live 2.0.6 is vulnerable to a local file inclusion vulnerability. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The crafted request contains a malicious file path in the ‘file’ parameter of the ‘module.php’ script. This allows an attacker to read sensitive files from the server.
Portaneo CMS 2.2.3 is vulnerable to a file upload vulnerability. The vulnerability exists in the ‘path/tools/fckeditor/editor/filemanager/connectors/php/config.php’ file, where the ‘$Config[‘Enabled’]’ parameter is set to ‘true’ by default, allowing an attacker to upload arbitrary files to the server.
A CSRF vulnerability exists in Boutique SudBox 1.2 which allows an attacker to change the login and password of the admin user. An attacker can craft a malicious HTML page containing a form with the action set to http://localhost/boutique/admin/password_2.php and the parameters admin and motdepasse set to the desired values. When the admin user visits the malicious page, the form will be automatically submitted and the login and password will be changed.
PHP Quick Arcade 3.0.21 is vulnerable to multiple vulnerabilities such as SQL Injection, XSS and Register_Global. An attacker can exploit these vulnerabilities to gain access to the database, execute arbitrary code and steal sensitive information.
The following script has authentication bypass. use ' or 1=1 or ''=' in both login and password.
The following script has authentication bypass. use ' or 1=1 or ''=' in both login and password.