Exploits
ogmenu-xss.txt
Drupal version 6.16 with OG Menu version 6.x-2.0 suffers from a cross site scripting vulnerability.
Categories: Exploits
adnetwork-xss.txt
Ad Network Script suffers from a cross site scripting vulnerability.
Categories: Exploits
simpgb-xss.txt
SimpGB versions 1.37.3 and below suffer from a cross site scripting vulnerability.
Categories: Exploits
zenphoto-xsrf.txt
Zenphoto CMS version 1.3 suffers from multiple cross site request forgery vulnerabilities.
Categories: Exploits
PR09-16.txt
Procheckup has found by making a malformed request to the Juniper IVE Web interface without authentication, that a vanilla cross site scripting (XSS) attack is possible.
Categories: Exploits
2daybizbc-sql.txt
2daybiz Businesscard Script suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Categories: Exploits
weblogic-inject.txt
Virtual Security Research, LLC. Security Advisory - Over the last several years, VSR analysts had observed unusual behavior in multiple WebLogic deployments when certain special characters were URL encoded and appended to URLs. In late April, 2010 VSR began researching this more in depth and found that the issue could allow for HTTP header injection and HTTP request smuggling attacks.
Categories: Exploits
diferiorcms-xsrf.txt
Diferior CMS version 8.01 suffers from multiple cross site request forgery vulnerabilities.
Categories: Exploits
struts2xwork-exec.txt
Struts2/XWork suffers from a remote command execution vulnerability.
Categories: Exploits
joomlaqcontacts-sql.txt
The Joomla QContacts component suffers from a remote SQL injection vulnerability.
Categories: Exploits
ajarticle-xss.txt
AJ Article suffers from a persistent cross site scripting vulnerability.
Categories: Exploits
customcms-xss.txt
CustomCMS suffers from a persistent cross site scripting vulnerability.
Categories: Exploits
asxtomp3-seh.txt
ASX to MP3 Converter version 3.1.2.1 SEH exploit with DEP and ASLR bypass for multiple OSes.
Categories: Exploits
ms10_042_helpctr_xss_cmd_exec.rb.txt
Help and Support Center is the default application provided to access online documentation for Microsoft Windows. Microsoft supports accessing help documents directly via URLs by installing a protocol handler for the scheme hcp . Due to an error in validation of input to hcp:// combined with a local cross site scripting vulnerability and a specialized mechanism to launch the XSS trigger, arbitrary command execution can be achieved. On IE7 on XP SP2 or SP3, code execution is automatic. If WMP9 is installed, it can be used to launch the exploit automatically. If IE8 and WMP11, either can be used to launch the attack, but both pop dialog boxes asking the user if execution should continue. This exploit detects if non-intrusive mechanisms are available and will use one if possible. In the case of both IE8 and WMP11, the exploit defaults to using an iframe on IE8, but is configurable by setting the DIALOGMECH option to none or player .
Categories: Exploits
diem-xss.txt
Diem version 5.1.2 suffers from multiple cross site scripting vulnerabilities.
Categories: Exploits
inetem-sql.txt
I-net Enquiry Management Script suffers from a remote SQL injection vulnerability.
Categories: Exploits
ari-lfixsrfxss.txt
Asterisk Recording Interface suffers from cross site request forgery, cross site scripting, denial of service, local file inclusion and path disclosure vulnerabilities.
Categories: Exploits
orbis-xsrf.txt
Orbis CMS version 1.0.2 suffers from multiple cross site request forgery vulnerabilities.
Categories: Exploits
