header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Online ID Generator 1.0 – Remote Code Execution (RCE)

The Online ID Generator 1.0 software is vulnerable to remote code execution (RCE) due to a bypass login SQL injection vulnerability and a shell upload exploit. An attacker can exploit these vulnerabilities to execute arbitrary code on the target system.

Webedition CMS v2.9.8.8 – Blind SSRF

The Webedition CMS v2.9.8.8 is vulnerable to a blind Server-Side Request Forgery (SSRF) attack. An attacker can exploit this vulnerability by sending a crafted request to the rpc.php file, specifically the widgetGetRss function. By manipulating the we_cmd[0] parameter, an attacker can make the server send a request to a specified URL, potentially bypassing access controls and retrieving sensitive information.

Cacti 1.2.24 – Authenticated command injection when using SNMP options

Under certain conditions, an authenticated privileged user can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server.

Recent Exploits: