header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Virgin Media Hub 3.0 Router – Denial of Service (PoC)

This exploit is a proof of concept for a denial of service vulnerability in the Virgin Media Hub 3.0 Router. The exploit sends a malicious HTTP request to the target router, which causes it to crash. No CVE is associated with this vulnerability.

Gate Pass Management System 2.1 – ‘login’ SQL Injection

Gate Pass Management System 2.1 is vulnerable to SQL Injection. An attacker can send a specially crafted HTTP POST request to the login-exec.php script with malicious SQL statements in the 'login' and 'password' parameters to execute arbitrary SQL commands in the application's database.

Anviz AIM CrossChex Standard 4.3 – CSV Injection

CSV (XLS) Injection (Excel Macro Injection or Formula Injection) exists in the AIM CrossChex 4.3 when importing or exporting users using xls Excel file. This can be exploited to execute arbitrary commands on the affected system via SE attacks when an attacker inserts formula payload in the 'Name' field when adding a user or using the custom fields 'Gender', 'Position', 'Phone', 'Birthday', 'Employ Date' and 'Address'. Upon importing, the application will launch Excel program and execute the malicious macro formula.

Fantastic Blog CMS 1.0 – ‘id’ SQL Injection

Fantastic Blog CMS version 1.0 is vulnerable to SQL injection. The application does not properly sanitize user-supplied input before using it in an SQL query. An attacker can exploit this vulnerability by sending malicious SQL queries to the application. This can allow the attacker to view, add, modify or delete data from the database.

Recent Exploits: