This Metasploit module exploits a vulnerability in PhpMyAdmin's setup feature which allows an attacker to inject arbitrary PHP code into a configuration file. The original advisory says the vulnerability is present in phpMyAdmin versions 2.11.x < 2.11.9.5 and 3.x < 3.1.3.1; this module was tested on 3.0.1.1. The file where our payload is written (phpMyAdmin/config/config.inc.php) is not directly used by the system, so it may be a good idea to either delete it or copy the running config (phpMyAdmin/config.inc.php) over it after successful exploitation.
daa773a35dac8ed474de87c4c695b7eaThe QuickTime Streaming Server contains a CGI script that is vulnerable to metacharacter injection, allow arbitrary commands to be executed as root.
648b5961f6898d673255697240f0f722This Metasploit module exploits various php include vulnerabilities.
6a900d61894d372ba65f60257f2764baThis Metasploit module exploits a metacharacter injection vulnerability in the FreeBSD and Solaris versions of the Zabbix agent. This flaw can only be exploited if the attacker can hijack the IP address of an authorized server (as defined in the configuration file).
f90accbcdb45c5a3c31cf84af285a418K-Rate suffers from a remote SQL injection vulnerability in view.php.
0eb2c822258d1a3c077096b50b28bea6UranyumSoft Ylan Servisi suffers from a remote database disclosure vulnerability.
99f9bb401166bc95576abd3546f05021WingFTP version 3.2.4 suffers from a cross site request forgery vulnerability.
863065cd82015c1735c4c9198872fee7Opera 10.10 suffers from a simple status bar obfuscation vulnerability.
e309d08aa14efd6fd2b5c28cec3270b5The Joomla RD Download component suffers from a local file disclosure vulnerability.
a0b954f3180823dd394b1a0004004b0eThe Joomla Airmonoblock component suffers from a remote blind SQL injection vulnerability.
ffc3a9fb011285025d338079488f74daMy Book World Edition NAS suffers from remote command execution and cross site scripting vulnerabilities.
603bb845511cbdced05e878c1fa933ccRoseOnlineCMS versions 3 B1 and below suffer from a local file inclusion vulnerability.
7c3f101d93c6c62c4bf98d9fc990c4b2I-Rater basic suffers from a remote shell upload vulnerability.
a415c2b476672743a6ed92199a269fa4PicMe version 2.1.0 suffers from a cross site scripting vulnerability.
accd871c0501d1a05ba6f137a192b4dcThe Mambo View Full Listing component suffers from a remote SQL injection vulnerability.
d1ab68aa2513bf1cf119076f1e1c2164Diesel Job Site version 1.4 suffers from remote file inclusion, cross site scripting, and bypass vulnerabilities.
4c41816e138d8cae391b80957b10dc01I-Escorts Directory suffers from a remote SQL injection vulnerability in country_escorts.php.
4b8aaefb06db33fdf4743f2993597d91PicMe version 2.1.0 suffers from a remote shell upload vulnerability.
f71a61cb63fbf097422a999d41eeefd5UBB.Threads version 6 suffers from remote file inclusion vulnerabilities.
e396b743da59c1a162f6900977487ad0The Joomla StaticXT component suffers from a cross site scripting vulnerability.
e581bf6d71e30d726a95f83d79568b3cScribd.com suffers from a cross site scripting vulnerability.
8210e4b01b01708960439dc6eb9a5628Netragard, L.L.C Advisory - Mac OS X Java Runtime suffers from buffer overflows that allow for remote code execution.
bf29ef8a7cb944628b6bfd65dacce73aB2B eCommerce suffers from a remote SQL injection vulnerability.
2eae3a31fdd8c09be5c3076e31685816The Joomla KKContent component suffers from a remote blind SQL injection vulnerability.
8f87f4dd1fce35d29d61a6999a2bba78Despe FreeCell suffers from a cross site scripting vulnerability.
c8e2b2b5064d991facb954e97565c43c