header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Proverbs Web Calendar SQL Injection Vulnerability

Proverbs Web Calendar is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Directory Traversal Vulnerability in Sentinel Protection Server and Keys Server

The Sentinel Protection Server and Keys Server are vulnerable to a directory-traversal vulnerability. This vulnerability occurs due to insufficient sanitization of user-supplied input data. An attacker can exploit this vulnerability to access sensitive information, which can be used for further attacks.

HTML-injection vulnerabilities in GWExtranet

GWExtranet is prone to multiple HTML-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input data before using it in dynamically generated content. Attacker-supplied HTML and script code could execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Cross-Site Scripting Vulnerability in PHPSlideShow

The PHPSlideShow application fails to properly sanitize user-supplied data, leading to a cross-site scripting vulnerability. Attackers can exploit this vulnerability to execute arbitrary HTML or script code in a user's browser session within the context of the affected site. This can result in the theft of authentication credentials and the ability to launch further attacks.

Buffer-Overflow Vulnerability in RichFX Basic Player ActiveX Control

The RichFX Basic Player ActiveX Control is prone to a buffer-overflow vulnerability due to inadequate boundary checks on user-supplied data. Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control, typically Internet Explorer. Failed exploit attempts may result in denial-of-service conditions.

Cross-site Scripting Vulnerability in VBTube

The VBTube application is prone to a cross-site scripting vulnerability due to insufficient sanitization of user-supplied data. An attacker can exploit this vulnerability to execute arbitrary HTML or script code in a user's browser session, potentially leading to the theft of cookie-based authentication credentials and the ability to launch further attacks.

VMware Tools Privilege Escalation Vulnerability

The VMware Tools application fails to properly drop privileges before performing certain functions, allowing an attacker to exploit this vulnerability in the guest operating system to elevate privileges in the host operating system.

Recent Exploits: