The vulnerability exists in the news.php script, which allows an attacker to inject arbitrary SQL commands. The attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the news.php script, which contains the malicious SQL code. The attacker can then gain access to the database and extract sensitive information such as usernames and passwords.
MMHAQ CMS is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending a crafted SQL query to the vulnerable parameter 'id' in the 'index.php' page. This can be used to extract the version of the database from the title bar of the browser.
Asset Manager is vulnerable to shell upload vulnerability. An attacker can upload a malicious shell file with the extension .php or .asp to the web server. For ASP shell File name can be like this : xxx.asp;xx.jpg
A vulnerability in the Joomla Component com_agenda 1.0.1 (id) allows an attacker to inject malicious SQL commands into the application. This can be exploited to gain access to the database and potentially gain access to sensitive information.
A buffer overflow vulnerability exists in Tembria Server Monitor 5.6.0 which can be exploited by sending a specially crafted HTTP request containing an overly long string of 'B' characters followed by an 'A' character. This can cause the application to crash, resulting in a denial of service condition.
The kernel allows processes to access the internal '.reiserfs_priv' directory at the top of a reiserfs filesystem which is used to store xattrs. Permissions are not enforced in that tree, so unprivileged users can view and potentially modify the xattrs on arbitrary files.
This vulnerability allows an attacker to upload malicious files to a vulnerable web server. The vulnerable web server is identified by a dork inurl:post.php?Category=Garage. After the malicious file is uploaded, it can be accessed via http://[site]/up_files/YouRShell.php
An attacker can exploit a SQL injection vulnerability in the Joomla component huruhelpdesk to gain access to the database. The attacker can send a malicious SQL query to the vulnerable parameter cid[0] in the URL. This will allow the attacker to view the username and password of the users in the database.
A Local File Inclusion (LFI) vulnerability exists in Joomla Component JA Voice. An attacker can exploit this vulnerability to include arbitrary files from the local system, which can lead to the disclosure of sensitive information.
A vulnerability exists in foobla Suggestions version 1.5.1.2 which allows an attacker to include a local file by manipulating the 'controller' parameter in the URL. An attacker can exploit this vulnerability to gain access to sensitive information.