header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Unauthenticated Arbitrary File Upload Vulnerability In Pydio/AjaXplorer 5.0.3 – 3.3.5

This exploit allows an attacker to upload arbitrary files to any location on the server via directory traversal. The vulnerability exists in the save_zoho.php file, specifically in the handling of the 'format' and 'name' parameters. If the 'ajxp_action' parameter is not set, the exploit uploads the 'content' file to the specified location. If the 'ajxp_action' parameter is set to 'get_file', the exploit reads the file from the specified location and then deletes it. The exploit takes advantage of the lack of sanitization of the 'format' and 'name' parameters.

phpTransformer 2016.9 – SQL Injection

The phpTransformer 2016.9 software is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a crafted request to the GeneratePDF.php file, specifically the idnews parameter. This allows the attacker to execute arbitrary SQL queries and potentially gain unauthorized access to the database.

Softbiz Banner Exchange Network Script ver 1 SQL INJECTION

The Softbiz Banner Exchange Network Script ver 1 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting malicious SQL code in the 'id' parameter of the 'campaign_stats.php' page. By doing so, the attacker can bypass authentication and retrieve sensitive information such as the admin username and password.

Recent Exploits: