The vulnerability allows an attacker to inject malicious SQL queries via the 'cid' and 'itemid' parameters in the 'gallery.php' and 'view_items.php' scripts. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation may allow an attacker to gain access to the admin panel of the application.
This Python script acts as a web server and sends a malformed long string to the CSS <style> tag, which can lead to remote code execution.
A buffer overflow vulnerability exists in MediaCoder, which is a free universal media transcoder. The vulnerability is caused due to a boundary error when handling user-supplied data, which can be exploited to cause a stack-based buffer overflow by e.g. a specially crafted .m3u file. This can be exploited to execute arbitrary code by overwriting a Structured Exception Handler (SEH) with a POP POP RETN instruction and passing an exception. The shellcode can be positioned anywhere in memory and an egghunter can be placed at the top of the stack frame to search for the shellcode and execute it.
Maian Uploader v4.0 is vulnerable to a shell upload vulnerability. An attacker can exploit this vulnerability by creating an account on the application, uploading a malicious file and accessing it via the user_uploads directory. This vulnerability can be exploited to gain remote code execution on the server.
PBBoard Version 2.0.5 is vulnerable to multiple vulnerabilities, including an Add Admin vulnerability, an upload vulnerability, and a file inclusion vulnerability. The Add Admin vulnerability allows an attacker to add an admin user to the system. The upload vulnerability allows an attacker to upload malicious files to the system. The file inclusion vulnerability allows an attacker to include malicious files from the system.
The vulnerability allows an attacker to traverse directories and execute malicious code on the vulnerable server. An attacker can send a specially crafted HTTP request containing directory traversal strings (e.g. ../../../../../../../../boot.ini) to the vulnerable server in order to traverse directories and read sensitive files. Additionally, an attacker can inject malicious JavaScript code into the vulnerable web application via the 'pg' parameter in the 'index.php' script. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Finally, an attacker can exploit the 'path' parameter in the 'form.php' script to include arbitrary remote files from external sources.
The vulnerability exists in the 'view_items.php' and 'store_info.php' scripts of the Softbiz Auktios Script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL statements to the vulnerable script. This can allow the attacker to gain access to the admin credentials stored in plaintext in the database.
A SQL injection vulnerability exists in phpCOIN 1.2.1, which allows an attacker to execute arbitrary SQL commands via the mod.php?mod=faq&mode=show&faq_id= parameter. An attacker can exploit this vulnerability to gain access to sensitive information such as usernames and passwords stored in the database.
ShortCMS v. 1.11F(B) is vulnerable to a SQL injection vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script printview.php?func=con&pvid= with a SQL payload. This will allow the attacker to extract sensitive information from the database.
This exploit tricks a user into accessing a malicious website by using a malicious link. The malicious link is embedded in the HTML code, which is triggered when the user hovers over the link. The malicious link redirects the user to a malicious website, while the user is under the impression that they are accessing a legitimate website.