• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

injection

  1. 1

    Exploits Karenderia CMS 5.1 Content Injection

    Karenderia CMS version 5.1 suffers from an iframe injection vulnerability. View the full article
  2. itsMe

    sqlmap v1.3.7 automates the process of detecting and exploiting SQL injection flaws

    Sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches...
  3. 1

    Exploits Linux Mint 19.1 yelp Command Injection

    This Metasploit module exploits a vulnerability within the "ghelp", "help" and "man" URI handlers within Linux Mint's "ubuntu-system-adjustments" package. Invoking any one the URI handlers will call the python script "/usr/local/bin/yelp" with the contents of the supplied URI handler as its...
  4. 1

    Exploits Mac OS X TimeMachine (tmdiagnose) Command Injection Privilege Escalation

    This Metasploit module exploits a command injection in TimeMachine on macOS <= 10.14.3 in order to run a payload as root. The tmdiagnose binary on OSX <= 10.14.3 suffers from a command injection vulnerability that can be exploited by creating a specially crafted disk label. The tmdiagnose...
  5. 1

    Exploits Carpool Web App 1.0 Cross Site Scripting / SQL Injection

    Carpool Web App version 1.0 suffers from cross site scripting and remote SQL injection vulnerabilities. View the full article
  6. 1

    Exploits EA Origin Template Injection Remote Code Execution

    EA Origin versions prior to 10.5.36 suffer from a remote code execution vulnerability via template injection leveraging cross site scripting. View the full article
  7. 1

    Exploits FaceSentry Access Control System 6.4.8 Remote Command Injection

    FaceSentry Access Control System version 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' and 'strInPort' parameters (POST) in pingTest and...
  8. 1

    Exploits Premier Ilan Scripti 1 SQL Injection

    Premier Ilan Scripti version 1 suffers from a remote SQL injection vulnerability. View the full article
  9. 1

    Exploits Varient 1.6.1 SQL Injection

    Varient version 1.6.1 suffers from a remote SQL injection vulnerability. View the full article
  10. 1

    Exploits CiuisCRM 1.6 SQL Injection

    CiuisCRM version 1.6 suffers from a remote SQL injection vulnerability. View the full article
  11. 1

    Exploits WorkSuite PRM 2.4 SQL Injection

    WorkSuite PRM version 2.4 suffers from a remote SQL injection vulnerability. View the full article
  12. 1

    Exploits dotProject 2.1.9 SQL Injection

    dotProject version 2.1.9 suffers from multiple remote SQL injection vulnerabilities. View the full article
  13. 1

    Exploits AZADMIN CMS Of HIDEA 1.0 SQL Injection

    AZADMIN CMS of HIDEA version 1.0 suffers from a remote SQL injection vulnerability. View the full article
  14. 1

    Exploits WebERP 4.15 SQL Injection

    WebERP version 4.15 suffers from a remote SQL injection vulnerability. View the full article
  15. 1

    Exploits BlogEngine.NET 3.3.6 / 3.3.7 XML Injection

    BlogEngine.NET versions 3.3.6 and 3.3.7 suffer from an XML external entity injection vulnerability. View the full article
Back
Top