source: https://www.securityfocus.com/bid/52046/info
Tube Ace is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/search/?q=%22%3E%3Cscript%3Ealert%28%22pwned%22%29%3C/script%3E&channel=
.png.c9b8f3e9eda461da3c0e9ca5ff8c6888.png)
A group blog by Leader in
Hacker Website - Providing Professional Ethical Hacking Services
-
Entries
16114 -
Comments
7952 -
Views
863138722
About this blog
Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.
Entries in this blog
source: https://www.securityfocus.com/bid/52043/info
PHP is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to exhaust available memory, denying access to legitimate users.
PHP versions prior to 5.3.9 are vulnerable.
<?php
while (true)
{
strtotime('Monday 00:00 Europe/Paris'); // Memory leak
}
?>
source: https://www.securityfocus.com/bid/52053/info
CMS Faethon is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CMS Faethon 1.3.4 is vulnerable; other versions may also be affected.
http://www.example.com/articles.php?by_author=[SQL]
http://www.example.com/article.php?id=[SQL]
source: https://www.securityfocus.com/bid/52058/info
Pandora FMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Pandora FMS 4.0.1 is vulnerable; other versions may also be affected.
http://www.example.com/[ Path ]/index.php?sec=services&sec2=[FILE INCLUDE VULNERABILITY!]

ButorWiki 3.0 - 'service' Cross-Site Scripting
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

SevenIT SevDesk 3.10 - Multiple Web Vulnerabilities
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Mobile Drive HD 1.8 - Local File Inclusion
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

OpenBSD 5.6 - Multiple Local Kernel Panics (Denial of Service)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

WordPress Plugin MiwoFTP 1.0.5 - Arbitrary File Download (2)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

WordPress Plugin Ultimate Product Catalogue - SQL Injection (1)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

JaWiki - 'versionNo' Cross-Site Scripting
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

Wifi Drive Pro 1.2 iOS - Local File Inclusion
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Photo Manager Pro 4.4.0 iOS - Local File Inclusion
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Photo Manager Pro 4.4.0 iOS - Code Execution
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

WordPress Plugin NEX-Forms < 3.0 - SQL Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

MooPlayer 1.3.0 - 'm3u' Local Buffer Overflow (SEH) (2)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

WebUI 1.5b6 - Remote Code Execution
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

WordPress Plugin Ultimate Product Catalogue - SQL Injection (2)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Free MP3 CD Ripper 2.6 2.8 - '.wav' File Buffer Overflow (SEH)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

R2/Extreme 1.65 - Stack Buffer Overflow / Directory Traversal
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view