header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

HotWeb Rentals SQL Injection Vulnerability

HotWeb Rentals is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.

Multiple SQL Injection Vulnerabilities in MyBB

MyBB is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Cross-Site Scripting (XSS) in Accept Signups Plugin for WordPress

The Accept Signups Plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Joomla! Classified Component SQL Injection

The Joomla! Classified component is prone to an SQL-injection vulnerability. This vulnerability occurs because the component fails to properly sanitize user-supplied input before using it in an SQL query. An attacker can exploit this issue to manipulate SQL queries, which may allow them to bypass the authentication mechanism and gain unauthorized access to the application or the underlying database. This could lead to the compromise of sensitive information, data modification, or the exploitation of other latent vulnerabilities in the database.

HTML-injection vulnerability in ImpressCMS

ImpressCMS is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

Mediatricks Viva Thumbs Plugin for WordPress Information Disclosure Vulnerabilities

The Mediatricks Viva Thumbs plugin for WordPress is prone to multiple information-disclosure vulnerabilities because it fails to properly sanitize user-supplied input. Attackers can exploit these issues using directory-traversal strings to confirm the existence of local files outside of the WordPress webroot. Information obtained can aid in launching further attacks.

Recent Exploits: