header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

TurboFTP 5.30 Build 572 Multiple Remote DoS

The TurboFTP application is vulnerable to multiple remote denial of service attacks. These include handling responses with a large number of newline characters, a heap overflow triggered by a long file name in a LIST command response, and a heap overflow when the application sends a long CWD command. These vulnerabilities can be exploited to cause a denial of service condition on the target system. It is unlikely that code execution is possible with these vulnerabilities.

Online Web Building v2.0 (id) Remote SQL Injection

This exploit allows an attacker to perform SQL injection on the Online Web Building v2.0 (id) application. By injecting SQL code into the 'art_id' parameter of the 'page.asp' page, an attacker can retrieve sensitive information such as usernames and passwords from the 'Users' table.

Advisory ID: HTB23212

High-Tech Bridge Security Research Lab discovered CSRF and Remote Code Execution vulnerabilities in EGroupware, which can be exploited by remote attacker to gain full control over the application and compromise vulnerable system.

NukeSentinel 2.5.05 (nsbypass.php) Blind SQL Injection Exploit

This exploit targets NukeSentinel version 2.5.05 and specifically the file 'nsbypass.php'. It allows an attacker to perform blind SQL injection attacks. The exploit requires certain conditions to be met, such as PHP and CMS conditions, and the victim's username and URL. Additional options can be specified, such as whether the victim is an admin or a normal user, the table prefix, the number of hits to try, and proxy settings.

Multiple vulnerabilities in CuteNews and UTF-8 CuteNews

The vulnerabilities in CuteNews and UTF-8 CuteNews allow attackers to obtain sensitive information, gain unauthorized access, run arbitrary script code in the browser, hijack user sessions, and execute arbitrary commands in the context of the webserver process. Exploits for some of the issues may require administrator privilege.

Recent Exploits: