header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

SQL-injection vulnerabilities in Joomla! Machine Component

The Machine component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

TheCartPress WordPress Plugin Local PHP File Inclusion and Cross-Site Scripting Vulnerabilities

Input passed via the 'tcp_box_path' HTTP POST parameter passed to '/wp-admin/admin.php?page=checkout_editor_settings' URL is not properly verified before being used in PHP 'include()' function, and can be abused to include arbitrary local files via directory traversal sequences. An attacker with administrator privileges can exploit this vulnerability to execute arbitrary PHP code and disclose sensitive data. Additionally, the plugin is vulnerable to Cross-Site Scripting attacks via CSRF vectors.

Recent Exploits: