header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

IPB <=2.1.4 exploit

The bug is in the pm system so a registered user can extract a password hash from the forum's data base of the target user. The exploit requires the target user's member ID which can be found under their avatar next to one of their posts. Once the hash is obtained, all forum cookies can be unset and the member_id and pass_hash can be set to the target user's member id and hash respectively.

Aardvark Topsites PHP <=4.2.2 Remote Command Execution Exploit

Aardvark Topsites PHP is vulnerable to a remote command execution vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This exploit uses the lostpw.php file to execute arbitrary commands on the vulnerable server.

NoticeBoardPro 1.0 SQL Injection & Arbitrary Upload

A sql injection vulnerability in NoticeBoardPro 1.0 can be exploited to extract arbitrary data. In some environments it may be possible to create a PHP shell. An arbitrary upload vulnerability in NoticeBoardPro 1.0 can be exploited to upload a PHP shell.

Knowledge Base Mod for PHPbb <= 2.0.2 remote file inclusion

The Knowledge Base Mod for PHPbb <= 2.0.2 is vulnerable to a remote file inclusion vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This request contains a malicious URL in the module_root_path parameter of the /includes/kb_constants.php file. This malicious URL can be used to execute arbitrary code on the vulnerable server.

Recent Exploits: