TrinTiTTY

7 exploits Active since Dec 2006
CVE-2007-3292 EXPLOITDB perl WORKING POC
Livecms - Unrestricted File Upload
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article.
CVE-2007-3291 EXPLOITDB perl WORKING POC
Livecms - XSS
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.
CVE-2007-3290 EXPLOITDB perl WORKING POC
LiveCMS <3.4 - Info Disclosure
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.
CVE-2007-2181 EXPLOITDB python WORKING POC
Webinsta FM Manager <0.1.4 - RCE
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.
CVE-2006-6765 EXPLOITDB perl WORKING POC
Pagetool 1.07 - RCE
Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execute arbitrary PHP code via (1) a local filename or FTP/share URI in the config_file parameter or (2) a URL in the ptconf[src] parameter.
CVE-2007-3293 EXPLOITDB perl WORKING POC
Livecms - SQL Injection
SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2007-4055 EXPLOITDB python WORKING POC
SimpleBlog 3.0 - SQL Injection
SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this may be related to CVE-2006-4300.