Turbo Traffic Trader Nitro version 1.0 is susceptible to multiple cross site scripting and SQL injection attacks. Full exploitation for the SQL injection attack provided.
f97ca616c43e652dfe2c9583e834a64932f03512bef096f4d9c26c7aa3a171ad
There is no user input sanitation for some parameters in trade.php in CJOverkill version 4.0.3, allowing for cross site scripting attacks to take place.
fb8ec6223316254b7134b54190da91977cf5dee5771fab54f779e3ca86aae2bc
Serendipity 0.7-beta1 and below proof of concept SQL injection exploit that dumps the administrator's username and md5 password hash.
0921a8c65327c27213316b4ea2d5b801a1e0596f4384dfe6d3868e19d39cc355
Proof of concept PHP exploit that makes use of a SQL injection vulnerability in TorrentTrader version 1.0 RC2.
9dce80108f836bd4eddb0de491a4df30d5452b7e1a68e5c6138b0452f93c7280
PHP based exploit for Gallery versions 1.4.4 and below that makes use of an arbitrary file upload flaw.
b806e5a726748ac3e812380c5c54072f07a8feb8a713637a035694778211fc2d
PHP based exploit for YaPiG 0.x that allows for an attacker to create arbitrary files on a vulnerable server.
d84ef4efc63ad0141d177a09b8ac9eb78fe82f50b463c66537c20e53232f892a
Nucleus CMS version 3.01 addcoment/itemid SQL Injection Proof of Concept PHP exploit that dumps the username and md5 hash of the password for the administrator user.
f381b9e4184efeb21af8394ab8bfa4585b0b12a1ecc75b4d37d1c396de95e22d