Twenty Year Anniversary
Showing 51 - 75 of 4,670 RSS Feed

PHP Files

WordPress Ultimate Product Catalog 4.2.24 PHP Object Injection
Posted Oct 30, 2017
Authored by tomplixsee

WordPress Ultimate Product Catalog plugin versions 4.2.24 and below suffer from a PHP object injection vulnerability.

tags | exploit, php
MD5 | 3f4ffd5d0fa22e90026bf5db1d8f6c0b
PHP 4.2.0 / 4.2.1 Remote Compromise / Denial Of Service
Posted Oct 27, 2017
Authored by Stefan Esser

PHP versions 4.2.0 and 4.2.1 suffer from an issue where depending on the processor architecture it may be possible for a remote attacker to either crash or compromise the web server.

tags | advisory, remote, web, denial of service, php
MD5 | e966da86f2a1eebadb8468cec478394a
PHP Melody 2.6.1 SQL Injection
Posted Oct 25, 2017
Authored by Venkat Rajgor

PHP Melody version 2.6.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | d1030b2d22474e4e4a43dd856b933af5
Tuleap 9.6 Second-Order PHP Object Injection
Posted Oct 24, 2017
Authored by EgiX | Site karmainsecurity.com

Tuleap versions 9.6 and below suffer from a second order PHP object injection vulnerability.

tags | advisory, php
advisories | CVE-2017-7411
MD5 | 2a4b257f70f6f54a3226a84d41b3ca08
PHP Melody 2.7.3 Cross Site Scripting / SQL Injection
Posted Oct 12, 2017
Authored by Paulos Yibelo

PHP Melody version 2.7.3 suffers from cross site scripting and SQL injection vulnerabilities.

tags | exploit, php, vulnerability, xss, sql injection
MD5 | 8d8544bc3a6ba55df5cbb4bfaefe5794
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
Posted Oct 12, 2017
Authored by mr_me, Mehmet Ince | Site metasploit.com

This Metasploit module exploits the authentication bypass and command injection vulnerability together. Unauthenticated users can execute a terminal command under the context of the web server user. The specific flaw exists within the management interface, which listens on TCP port 443 by default. Trend Micro IMSVA product have widget feature which is implemented with PHP. Insecurely configured web server exposes diagnostic.log file, which leads to an extraction of JSESSIONID value from administrator session. Proxy.php files under the mod TMCSS folder takes multiple parameter but the process does not properly validate a user-supplied string before using it to execute a system call. Due to combination of these vulnerabilities, unauthenticated users can execute a terminal command under the context of the web server user.

tags | exploit, web, php, tcp, vulnerability
MD5 | c596a4696eab69db88b173ffa1c4b5fb
X-Cart 5.2.23 / 5.3.1.9 / 5.3.2.13 / 5.3.3 PHP Code Injection
Posted Oct 12, 2017
Authored by sxcurity

X-Cart versions 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 suffer from a PHP code injection vulnerability.

tags | exploit, php
MD5 | 517d89663c7dc4f461e8a51d590a30bf
Trend Micro OfficeScan Remote Code Execution
Posted Oct 10, 2017
Authored by mr_me, Mehmet Ince | Site metasploit.com

This Metasploit module exploits the authentication bypass and command injection vulnerability together. Unauthenticated users can execute a terminal command under the context of the web server user. The specific flaw exists within the management interface, which listens on TCP port 443 by default. The Trend Micro Officescan product has a widget feature which is implemented with PHP. Talker.php takes ack and hash parameters but doesn't validate these values, which leads to an authentication bypass for the widget. Proxy.php files under the mod TMCSS folder take multiple parameters but the process does not properly validate a user-supplied string before using it to execute a system call. Due to combination of these vulnerabilities, unauthenticated users can execute a terminal command under the context of the web server user.

tags | exploit, web, php, tcp, vulnerability
MD5 | 02f022c47acfeb55ae34578721c1b3be
PHP Multi Vendor Script 1.02 SQL Injection
Posted Oct 1, 2017
Authored by 8bitsec

PHP Multi Vendor Script version 1.02 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 3e127f8c407e6c4653405c02e469d49c
PHP CityPortal 2.0 SQL Injection
Posted Sep 29, 2017
Authored by Ihsan Sencan

PHP CityPortal version 2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | ab34a7a0ef59aefc13293ec209d12e32
Easy Blog PHP Script 1.3a SQL Injection
Posted Sep 29, 2017
Authored by 8bitsec

Easy Blog PHP Script version 1.3a suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | fa89f896f402771ab795844cdedf5a00
TrendMicro OfficeScan 11.0 / XG (12.0) Information Disclosure
Posted Sep 29, 2017
Authored by hyp3rlinx | Site hyp3rlinx.altervista.org

TrendMicro OfficeScan versions 11.0 and XG (12.0) suffer from NT domain and PHP information disclosure vulnerabilities.

tags | exploit, php, vulnerability, info disclosure
advisories | CVE-2017-14085
MD5 | 8849cad3ac8077aaabee386cf3a4f609
FLIR Systems FLIR Thermal Camera PT-Series (PT-334 200562) Remote Root
Posted Sep 25, 2017
Authored by LiquidWorm | Site zeroscience.mk

FLIR Camera PT-Series suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exist due to several POST parameters in controllerFlirSystem.php script when calling the execFlirSystem() function not being sanitized when using the shell_exec() PHP function while updating the network settings on the affected device. This allows the attacker to execute arbitrary system commands as the root user and bypass access controls in place.

tags | exploit, remote, arbitrary, root, php, vulnerability
MD5 | 5ddf109d3a422df75105565034f680b0
Gentoo Linux Security Advisory 201709-21
Posted Sep 25, 2017
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201709-21 - Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary code. Versions less than 5.6.31:5.6 are affected.

tags | advisory, arbitrary, php, vulnerability
systems | linux, gentoo
advisories | CVE-2017-11362, CVE-2017-11628, CVE-2017-12932
MD5 | e37ef91858dce51d5410cc67c898748f
PHP Auction Ecommerce Script 1.6 SQL Injection
Posted Sep 22, 2017
Authored by 8bitsec

PHP Auction Ecommerce Script version 1.6 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 1bbb761c85a0eeb2c41619563fcc7584
Carlo Gavazzi Powersoft 2.1.1.1 Directory Traversal
Posted Sep 15, 2017
Authored by James Fitts | Site metasploit.com

This Metasploit module exploits a directory traversal vulnerability found in Carlo Gavazzi Powersoft versions 2.1.1.1 and below. The vulnerability is triggered when sending a specially crafted GET request to the server. The location parameter of the GET request is not sanitized and the sendCommand.php script will automatically pull down any file requested

tags | exploit, php, file inclusion
MD5 | 7ead626f719b2712cc6f6e65a79e2c9f
PHP Dashboards NEW 4.4 SQL Injection
Posted Sep 12, 2017
Authored by Ihsan Sencan

PHP Dashboards NEW version 4.4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | db1a533b5870ca5c881efd5b9d56039e
PHP Dashboards NEW 4.4 Arbitrary File Read
Posted Sep 12, 2017
Authored by Ihsan Sencan

PHP Dashboards NEW version 4.4 suffers from an arbitrary file read vulnerability.

tags | exploit, arbitrary, php
MD5 | 62b7d50497d65bc8022a41ef2f61bdac
jRank Topsites 1.0 Cross Site Request Forgery / Code Injection
Posted Sep 9, 2017
Authored by Ihsan Sencan

jRank Topsites version 1.0 suffers from a cross site request forgery vulnerability that allows for PHP code injection vulnerability.

tags | exploit, php, csrf
MD5 | f9c9dacf3c805760fedafa777dff54be
Advertiz PHP Script 0.2 Cross Site Request Forgery
Posted Sep 7, 2017
Authored by Ihsan Sencan

Advertiz PHP Script version 0.2 suffers from a cross site request forgery vulnerability.

tags | exploit, php, csrf
MD5 | fd1b21d9f8c84d00c07247ec58d57074
HP Security Bulletin HPESBHF03770 1
Posted Aug 28, 2017
Authored by HP | Site hp.com

HP Security Bulletin HPESBHF03770 1 - A potential security vulnerability has been identified in Comware 7 MSR Routers using PHP, Go, Apache Http Server, and Tomcat. The vulnerability known as "httpoxy" could be remotely exploited to execute arbitrary code. Revision 1 of this advisory.

tags | advisory, web, arbitrary, php
advisories | CVE-2016-5385, CVE-2016-5386, CVE-2016-5387, CVE-2016-5388
MD5 | e89a7ac16ee1b5fb1e53d79ab6e79b09
IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution
Posted Aug 22, 2017
Authored by securiteam | Site metasploit.com

This Metasploit module exploits an unauthenticated remote PHP code execution vulnerability in IBM OpenAdmin Tool included with IBM Informix versions 11.5, 11.7, and 12.1. The 'welcomeServer' SOAP service does not properly validate user input in the 'new_home_page' parameter of the 'saveHomePage' method allowing arbitrary PHP code to be written to the config.php file. The config.php file is executed in most pages within the application, and accessible directly via the web root, resulting in code execution. This Metasploit module has been tested successfully on IBM OpenAdmin Tool 3.14 on Informix 12.10 Developer Edition (SUSE Linux 11) virtual appliance.

tags | exploit, remote, web, arbitrary, root, php, code execution
systems | linux, suse
advisories | CVE-2017-1092
MD5 | b78839adcfa2b9b750dba9d03fc684b8
PHP Coupon Script 6.0 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

PHP Coupon Script version 6.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 4d5d302c3fc2243a45c1479db0daa87e
PHP-Lance 1.52 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

PHP-Lance version 1.52 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | e8d2d0097ba26f9be292396680c25676
PHP Jokesite 2.0 SQL Injection
Posted Aug 21, 2017
Authored by Ihsan Sencan

PHP Jokesite version 2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 74908aabc66977a18175cabb83584b15
Page 3 of 187
Back12345Next

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

April 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    5 Files
  • 2
    Apr 2nd
    17 Files
  • 3
    Apr 3rd
    11 Files
  • 4
    Apr 4th
    21 Files
  • 5
    Apr 5th
    17 Files
  • 6
    Apr 6th
    12 Files
  • 7
    Apr 7th
    1 Files
  • 8
    Apr 8th
    6 Files
  • 9
    Apr 9th
    21 Files
  • 10
    Apr 10th
    18 Files
  • 11
    Apr 11th
    42 Files
  • 12
    Apr 12th
    7 Files
  • 13
    Apr 13th
    14 Files
  • 14
    Apr 14th
    1 Files
  • 15
    Apr 15th
    1 Files
  • 16
    Apr 16th
    15 Files
  • 17
    Apr 17th
    20 Files
  • 18
    Apr 18th
    24 Files
  • 19
    Apr 19th
    20 Files
  • 20
    Apr 20th
    7 Files
  • 21
    Apr 21st
    10 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close