A local file inclusion vulnerability exists in the Joomla component Horoscope, which allows an attacker to include a file from the local system. This can be exploited to disclose sensitive information by including files from the local system, such as the /etc/passwd file.
A local file inclusion vulnerability exists in the Joomla Component Web TV. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing directory traversal characters to the vulnerable application. This can allow the attacker to include a file from the local system or a remote system that the web server has access to.
A denial of service vulnerability exists in PHP 5.3.0 when using the getopt() function. By passing a large string of 'A:' characters, the getopt() function will cause a segmentation fault, resulting in a denial of service.
A remote file inclusion vulnerability exists in YaPig V0.94.0u, which allows an attacker to include a remote file on the web server. This can be exploited to execute arbitrary PHP code by including a malicious file from a remote location. The vulnerability is due to the 'YAPIG_PATH' parameter in 'last_gallery.php' not properly sanitizing user-supplied input.
This is a vulnerability in the CMS created by the leading web development company Worldviewer.com. It allows attackers to inject malicious SQL code into vulnerable parameters in the URL. This can be exploited to gain access to the database and potentially sensitive information.
Joomla component mv_restaurantmenumanager is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter. This can allow the attacker to gain access to the database and extract sensitive information such as usernames and passwords.
HotNews 0.7.2 is vulnerable to Remote File Inclusion. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'config[incdir]' parameter. This will allow the attacker to execute arbitrary code on the vulnerable system.
Multi-Venue Restaurant Menu Manager (MVRMM) is vulnerable to SQL Injection. The vulnerable parameter is 'mid' and the vulnerable URL is http://some-cool-domain.tld/index.php?option=com_mv_restaurantmenumanager&task=menu_display&Venue=XX&mid=XX&Itemid=XX. Exploitation can be a little bit tricky.
Elite Gaming Ladders version 3.5 is vulnerable to a SQL injection vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This request contains malicious SQL statements that can be used to extract sensitive information from the database, such as user credentials.
Vulnerable URL: http://www.some-cool-domain.tld/index.php?view=docs&doc_id=XX. Exploit the vulnerability: http://www.some-cool-domain.tld/index.php?view=docs&doc_id=XX+AND+1=2+UNION+SELECT+concat(user()),concat(user()),concat(user()),concat(user()),5--