header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

VP-ASP 6.00 SQL Injection / Exploit

The SQL Injection bug is in the shopcurrency.asp file under the 'cid' query. A quick hack to add user a/a is '/shopcurrency.asp?cid=AUD';insert into tbluser ('fldusername','fldpassword','fldaccess') values ('a','a','1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29')--. To remove the user 'a', the command is '/shopcurrency.asp?cid=AUD';delete from tbluser where fldusername='a'--.

HiveMail <= 1.3 remote command execution exploit

HiveMail is vulnerable to a remote command execution vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malicious command in the 'command' parameter. This will allow the attacker to execute arbitrary commands on the vulnerable system.

RBAWStatsMigrate Exploit

This exploit is a python script that allows an attacker to execute arbitrary code on a vulnerable system. The exploit takes advantage of a vulnerability in the RBAWStatsMigrate module, which allows an attacker to inject malicious code into the system. The exploit then uses a perl one-line tcp connect-back code to connect to the attacker's system and execute the code.

Statit V4 Remote File Inclusion exploit

Statit V4 Remote File Inclusion exploit is a vulnerability that allows an attacker to include a remote file on the web server. This vulnerability is present in the Statit V4 web application. The attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable web application. The attacker can then execute arbitrary code on the web server.

Limbo CMS (option=weblinks) sql injection exploit

This exploit allows an attacker to gain access to the username and password of a user in the Limbo CMS system. The attacker can send a malicious GET request to the index.php page with the option=weblinks parameter and an additional parameter of catid=-1 union select 0,1,2,concat(char(0x6c,0x6f,0x67,0x69,0x6e,0x3a),username,char(0x20,0x70,0x61,0x73,0x73,0x77,0x6f,0x72,0x64,0x3a),password),4,5,6,7,8,9,10,11 from lm_users where id=[user_id]/*. This will return the username and password of the user with the specified user_id.

Recent Exploits: