header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

MODX Revolution CSRF Tokens Bypass + Reflected Cross Site Scripting + Stored XSS

The vulnerability allows an attacker to perform Cross-Site Scripting (XSS) attacks and bypass CSRF Tokens Protection. This can lead to various malicious activities such as taking over victim accounts, changing primary email addresses, sending forged requests, and tricking admins to attack their own users.

Multiple Cross-Site Scripting Vulnerabilities in Coppermine Photo Gallery

Coppermine Photo Gallery is prone to multiple cross-site-scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Multiple Input-Validation Vulnerabilities in CruxCMS

Multiple input-validation vulnerabilities, including security-bypass, arbitrary-file-upload, SQL-injection, local file-include, cross-site-scripting, and information-disclosure issues, allow unauthorized access, execution of scripts, data modification, stealing authentication credentials, and other attacks.

Cross-Site Scripting Vulnerability in LiveZilla

The LiveZilla software fails to properly sanitize user-supplied input, leading to a cross-site scripting vulnerability. An attacker can exploit this vulnerability by injecting arbitrary script code into the browser of a targeted user, potentially allowing them to steal authentication credentials and launch further attacks.

IBM Tivoli Access Manager for e-business Directory Traversal Vulnerability

IBM Tivoli Access Manager for e-business is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.

SQL Injection Vulnerability in Pligg CMS

Pligg CMS is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.

Cross-Site Scripting Vulnerability in Appweb

Appweb is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Recent Exploits: