header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

IPCalc Remote File Include Vulnerability

The vulnerability exists due to insufficient sanitization of user-supplied input passed to the 'type' and 'cgipath' parameters in 'ip.inc.php' script. A remote attacker can include arbitrary files from remote hosts and execute arbitrary code on the vulnerable system.

MP3 Streaming DownSampler for PHP v3.0 (fullpath) Remote File Include Exploit

The vulnerability exists due to insufficient sanitization of user-supplied input passed via the 'fullpath' parameter to the 'Core/core.inc.php' script. This can be exploited to include arbitrary files from remote locations by passing a URL in the 'fullpath' parameter. Successful exploitation requires that 'allow_url_include' is set to 'On' in the 'php.ini' configuration file.

freePBX v2.1.3

A remote file inclusion vulnerability exists in freePBX v2.1.3. The vulnerability is due to the 'require_once' function in the upgrade.php script, which allows an attacker to include arbitrary files from remote locations. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'amp_conf[AMPWEBROOT]' parameter.

PHPMyDesk 1.0beta Remote Command Execution Exploit

This exploit allows an attacker to execute arbitrary commands on a vulnerable system. The vulnerability exists in the viewticket.php file, which includes the pmd-config.php file. The pmd-config.php file contains a variable called $pmdlang, which is used to include a file from the lang directory. An attacker can use this vulnerability to include a remote file and execute arbitrary commands on the vulnerable system.

Hosting Controller 6.1 Hotfix <= 3.2 Multi Vuln.

UnAuthenticated user can delete every sites virtual directory on hc sites by forum, make forum virtual directory (with the desire name) for everysites on hc, disable all hc forums by SQL Injection, and enable all hc forums by SQL Injection. Bugs are available in 'DisableForum.asp' and 'enableForum.asp' in forum directory.

Php League v0.82 (classement.php) Remote SQL Injection Exploit

This exploit allows an attacker to inject malicious SQL commands into a vulnerable web application. The exploit is triggered when the application takes user input and inserts it into a SQL query without proper sanitization. This can allow an attacker to gain access to sensitive information, modify data, or even delete data from the database.

Coppermine Photo Gallery 1.4.9 Remote SQL Injection Vulnerability

This exploit allows an attacker to gain access to the Coppermine Photo Gallery 1.4.9 application by exploiting a Remote SQL Injection vulnerability. The attacker needs a valid user account to exploit this vulnerability. The exploit requires the host, path, table prefix, user id, username and password as parameters. The exploit uses the 'albmgr.php' script to inject a malicious SQL query and extract the user's password.

N/X 2002 Professional Edition Web CMS <= 4.1 (nxheader.inc.php) Remote File Include Exploit

N/X 2002 Professional Edition Web CMS version 4.1 is vulnerable to a remote file include vulnerability. This vulnerability allows an attacker to include a remote file, usually through a malicious URL, and execute it on the vulnerable server. This can lead to the execution of arbitrary code on the server.

Recent Exploits: