header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Myuploader >> upload shell exploit

A remote code execution vulnerability exists in Myuploader, which allows an attacker to upload a malicious shell and execute arbitrary code on the vulnerable system. The attacker can use the Dork to find vulnerable websites and then upload the shell to the ‘myuploader/uploaded-files/shell.php’ path. The attacker can then execute arbitrary code on the vulnerable system.

PHPDirector Game Edition Multiple Vulnerabilities (LFI/SQLi/Xss)

PHPDirector Game Edition is vulnerable to Local File Inclusion and SQL Injection. The Local File Inclusion vulnerability exists in the header.php file, where the ‘lang’ parameter is not properly sanitized. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. The SQL Injection vulnerability exists in the games.php file, where the ‘id’ parameter is not properly sanitized. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server.

ITaco Group ITaco.biz (view_news) SQL Injection Vulnerability

An attacker can exploit this vulnerability by sending a specially crafted SQL query to the vulnerable application. This can be done by appending the malicious SQL query to the vulnerable parameter in the HTTP request. This can allow the attacker to gain access to the database and execute arbitrary commands.

Novell Netware CIFS And AFP Remote Memory Consumption DoS

This exploit is a modified version of the script written by the researcher Jeremy Brown which is used to cause a remote memory consumption denial of service on Novell Netware 6.5 SP8. The script uses IO::Socket and String::Random modules to send a random string of size up to 666 bytes to the target on port 548.

YP Portal MS-Pro Surumu 1.0 DB Download Vulnerability

An attacker can download the database of YP Portal MS-Pro Surumu 1.0 by accessing the URL http://server/mspro12/galeri/database/db.mdb. An attacker can also login to the application by accessing the URL http://server/mspro12/galeri/yonet/admin.asp.

KMSoft Guestbook v 1.0 Database Disclosure Vulnerability

KMSoft Guestbook v 1.0 is vulnerable to a database disclosure vulnerability. An attacker can exploit this vulnerability by sending a malicious HTTP request to the vulnerable server. The request will return the database file (db.mdb) which contains sensitive information such as usernames, passwords, etc. The vulnerable URL is http://server/[dizin]/db/db.mdb.

LightOpen CMS Remote File Inclusion (smarty.php)

LightOpen CMS is vulnerable to a Remote File Inclusion vulnerability due to a lack of proper sanitization of user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'cwd' parameter of the 'smarty.php' script. This can allow an attacker to execute arbitrary code on the vulnerable system.

ImagoScripts Deviant Art Clone SQL Injection Vulnerability

A SQL injection vulnerability exists in ImagoScripts Deviant Art Clone, which allows an attacker to execute arbitrary SQL commands on the underlying database. This can be exploited by sending a specially crafted HTTP request to the vulnerable application. Successful exploitation could result in the execution of arbitrary SQL commands, disclosure of sensitive information, or even the complete compromise of the vulnerable system.

Recent Exploits: