header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Cross-Site Scripting in Advanced Text Widget plugin for WordPress

The Advanced Text Widget plugin for WordPress is prone to a cross-site-scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Cross-Site Scripting Vulnerability in Alert Before Your Post Plugin for WordPress

The Alert Before Your Post plugin for WordPress is vulnerable to cross-site scripting (XSS) due to inadequate input sanitization. An attacker can exploit this vulnerability by injecting arbitrary script code in the affected site's browser. This can lead to the theft of authentication credentials and enable further malicious activities.

Digital Attic Foundation CMS SQL Injection Vulnerability

The Digital Attic Foundation CMS is vulnerable to an SQL injection attack due to inadequate input sanitization. An attacker can manipulate the 'id' parameter in the 'index.php' page to inject malicious SQL code, potentially compromising the application, gaining unauthorized access to data, or exploiting other vulnerabilities in the underlying database.

XOOPS Module myAlbum-P <= 2.0 (cid) Remote BLIND SQL Injection Exploit

This exploit allows an attacker to perform a blind SQL injection attack in the myAlbum-P module of XOOPS CMS version 2.0 or earlier. By manipulating the 'cid' parameter in the viewcat.php file, an attacker can extract sensitive information from the database.

Multiple Cross-Site Scripting Vulnerabilities in GoAhead WebServer

The GoAhead WebServer is prone to multiple cross-site scripting vulnerabilities due to insufficient sanitization of user-supplied data. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of a victim user, potentially leading to the theft of authentication credentials and other attacks.

Cross-Site Scripting in Flexible Custom Post Type Plugin for WordPress

The Flexible Custom Post Type plugin for WordPress is vulnerable to cross-site scripting due to insufficient input sanitization. An attacker can exploit this vulnerability by injecting arbitrary script code into the affected site's browser, potentially leading to the theft of authentication credentials and other malicious activities.

Cross-Site Scripting Vulnerability in ZOHO ManageEngine ADSelfService Plus

ZOHO ManageEngine ADSelfService Plus is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

webERP Information Disclosure, SQL Injection, and Cross-Site Scripting Vulnerabilities

webERP is prone to information-disclosure, SQL-injection, and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input. An attacker may exploit the information-disclosure issue to gain access to sensitive information that may lead to further attacks. An attacker may exploit the SQL-injection issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Recent Exploits: