header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

MiniBILL v2006-10-10 (config[page_dir] Remote File Include Vulnerability

A remote file include vulnerability exists in MiniBILL v2006-10-10 due to improper validation of user-supplied input. An attacker can exploit this vulnerability to include arbitrary remote files, resulting in arbitrary code execution on the vulnerable system.

Multi-Page Comment System (RFI)

The Multi-Page Comment System (MPCS) is vulnerable to a Remote File Inclusion (RFI) vulnerability. An attacker can exploit this vulnerability by sending a malicious URL in the 'path' parameter of the 'include.php' and 'functions.php' scripts. This will allow the attacker to execute arbitrary code on the vulnerable system.

Comment IT (class_admin.php , class_comments.php) Remot File Include Vulnerability

A remote file include vulnerability exists in class_admin.php and class_comments.php of Comment IT. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request containing a URL in the PathToComment parameter. This can allow the attacker to include a remote file containing arbitrary code, resulting in arbitrary code execution.

Imageview <= 5 (Cookie/index.php) Remote Code Execution Exploit

Imageview 5 is vulnerable to a remote code execution vulnerability. This exploit works if uploading is enabled for any album. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malicious cookie containing PHP code. The code will be executed on the server.

Discuz! 5.0.0 GBK SQL injection / admin credentials disclosure exploit

Discuz! 5.0.0 GBK is vulnerable to an SQL injection vulnerability which allows an attacker to gain access to the admin credentials. The exploit sends a GET request to the target server with the path to Discuz! and then sends a POST request to the admin/index.php page with the formhash and admin credentials. If the exploit succeeds, the attacker will be able to gain access to the admin credentials.

Berty Forum <= 1.4(index.php) Remote Blind SQL Injection Exploit

Berty Forum <= 1.4(index.php) is vulnerable to a blind SQL injection vulnerability. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable application. This can allow the attacker to gain access to sensitive information stored in the database, such as user credentials and other confidential data.

Recent Exploits: