header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

CMS Firebrand Tec Local File Inclusion Vulnerability

A Local File Inclusion (LFI) vulnerability exists in CMS Firebrand Tec, which allows an attacker to include a file from the local file system of the web server. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. This can be done by appending a maliciously crafted string to the vulnerable parameter in the HTTP request. This can allow an attacker to include a file from the local file system of the web server, such as the application source code, configuration and critical system files, and even the web server’s password file.

SmodCMS v.4.07 (fckeditor) Remote Arbitrary File Upload Exploit

This exploit allows an attacker to upload arbitrary files to the vulnerable server. The vulnerability exists in the SmodCMS v.4.07 (fckeditor) application, due to the lack of proper validation of the uploaded files. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious file to the vulnerable server.

Guestbook PHP XSS Vulnerability

The guestbook fails to properly sanitize the user input when a new entry is added. When HTML/Java Script code is added, it gets displayed/parsed when the new entry was successfully submitted. Furthermore the code gets executed when the admin views the entries in the control panel. It is even possible to temporarily disable the admin features in the backend since the injected code gets executed before the admin buttons get displayed. When the correct code was injected, the design gets destroyed and the admin buttons disappear.

WHMCS control (WHMCompleteSolution) Sql Injection

An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. The request should contain malicious SQL statements in the parameters of the vulnerable page. This can allow the attacker to access or modify the data in the back-end database.

XSS and Authentication bypass in NCT Jobs Portal Script

NCT Jobs Portal script is a web product for running powerful and customized job portals. Be it a fresh site that you want to launch or be it for integration into your already existing website, NCT Jobs Portal is everything you need when it comes to job portal or business networking solution. Jobs Portal comes with a front-end and a back-end (Admin Panel). Admin Panel has a wide range of functions along with a CMS (Content Management System) which will easily enpower you to customize and manage your very own Jobs Portal. The following script has authentication bypass in the admin login use ' or 1=1 or ''=' in both login and password. XSS is also found in the search field. Parameter Name: Keywords or Tags or Desired City Parameter Type: Querystring Attack Pattern: '"--><script>alert(0x000872)</script>

ZipWrangler 1.20 (.zip) SEH 0day exploit

This exploit is for ZipWrangler 1.20 (.zip) SEH 0day vulnerability. It is a buffer overflow exploit which uses a local file header, central file header, end of central directory file header and a payload of 4064 A's, 6 bytes of NSEH, 4 bytes of SEH, 20 bytes of NOPs and a shellcode of 351 bytes. The exploit is written in Perl and is used to create a malicious zip file.

Recent Exploits: