philboard v1.02 is an ASP Web Forum vulnerable to SQL Injection. The vulnerability exists in the buscahost_forum.asp?forumid=1 parameter, which can be exploited by appending a malicious SQL query to the parameter value.
phpAuthent 0.2.1 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter 'nid' in the 'news_releases.php' file. This can allow the attacker to gain access to sensitive information such as usernames and passwords stored in the database.
A vulnerability was discovered in SiteDone Custom Edition 2.0 which allowed an attacker to inject malicious SQL queries and XSS payloads into the application. The vulnerability was discovered by d3v1l [Avram Marius] in March 2010 and was located in the detail.php page, where an attacker could inject a malicious SQL query or XSS payload via the articleId parameter. The malicious query or payload would then be executed by the application.
A Vulnerability has been discovered in Manage Engine Service Desk Plus, which can be exploited by malicious people to conduct SQL injection attacks. Input passed via the "woID" parameter to WorkOrder.do is not properly sanitized before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is confirmed in version 7.6. Other versions may also be affected.
mplayer <= 4.4.1 is vulnerable to a NULL pointer dereference. The vulnerability is triggered when mplayer tries to dereference eax, which is a NULL pointer. This can be exploited to cause a denial of service.
myMP3-Player v3.0 is vulnerable to a local buffer overflow exploit when a specially crafted .m3u file is opened. This exploit uses a short jump, a pop/pop/ret instruction, and a NOP sled followed by shellcode to execute arbitrary code. The exploit was tested on Windows XP SP3 (ger).
These are Full path disclosure, SQL Injection and Cross-Site Scripting vulnerabilities. Full path disclosure can be exploited by sending a crafted request to the vulnerable URL with a single quote character. SQL Injection can be exploited by sending a crafted request to the vulnerable URL with a malicious SQL query. XSS can be exploited by sending a crafted request to the vulnerable URL with a malicious script.
VariCAD is prone to a memcpy() over flow in the parsing of 4 byte value that is loaded into the ebx register. VariCAD-Viewer is also vulnerable to this attack although exploitation is harder due to the Varicad viewer being compiled with exception handler protection. The value that was loaded into the $EBX register was supplied by the offsets inside the file that was manipulated by user supplied data. To exploit the application open VariCAD 2010-2.05 EN then go to File --> Open --> Then chose the malicious dwb file.
This Bug Works when Register_Globals=On. A SQL Injection vulnerability exists in the ratedownload() function of modules.php in PHP-Nuke. The vulnerability is due to the lack of input validation of the 'lid' parameter when passed to the ratedownload() function. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
A vulnerability found in the memory management of the Virtual Machine Monitor makes memory pages mapped above the 2GB available with read or read/write access to user-space programs running in a Guest operating system. By leveraging this vulnerability it is possible to bypass security mechanisms of the operating system such as Data Execution Prevention (DEP) [1], Safe Structured Error Handling (SafeSEH) [2] and Address Space Layout Randomization (ASLR) [3] designed to prevent exploitation of security bugs in applications running on Windows operation systems.