r0t3d3Vil

117 exploits Active since Nov 2005
CVE-2005-4365 EXPLOITDB text WRITEUP
FLIP 0.9.0.1029 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php.
CVE-2005-3846 EXPLOITDB text WRITEUP
Fscripts Fantastic News < 2.1.1 - SQL Injection
SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
EIP-2026-107010 EXPLOITDB text WORKING POC
EZDatabaseRemote 2.0 - PHP Script Code Execution
CVE-2005-4302 EXPLOITDB text WRITEUP
ezDatabase <2.1.2 - Path Traversal
Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.
CVE-2005-4303 EXPLOITDB text WRITEUP
ezDatabase <2.1.2 - SQL Injection
SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.
CVE-2005-3845 EXPLOITDB text WRITEUP
Ezinvoiceinc EZ Invoice Inc - SQL Injection
SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email [email protected] and EZI will email you the patch to fix this small issue."
CVE-2005-4254 EXPLOITDB text WRITEUP
Dreamlevels Dream Poll - SQL Injection
SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2005-4311 EXPLOITDB text WRITEUP
DCForum <6.25 - XSS
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.
CVE-2005-4429 EXPLOITDB text WRITEUP
CS-Cart 1.3.0 - SQL Injection
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
CVE-2005-4385 EXPLOITDB text WRITEUP
Cofax 2.0 RC3- - XSS
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.
EIP-2026-106082 EXPLOITDB text WRITEUP
CommodityRentals 2.0 - SQL Injection
EIP-2026-106194 EXPLOITDB text WORKING POC
CourseForum Technologies ProjectForum 4.7 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4049 EXPLOITDB text WRITEUP
Netart Media Blog System - SQL Injection
Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.
CVE-2005-4381 EXPLOITDB text WRITEUP
Caravel CMS <3.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fileDN and (2) folderviewer_attrs parameters.
CVE-2005-4375 EXPLOITDB text WRITEUP
Amaxus <3 - XSS
Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.
CVE-2005-4596 EXPLOITDB text WRITEUP
AdesGuestbook 2.0 - XSS
Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter.
CVE-2005-3914 EXPLOITDB text WRITEUP
Affcommerce - SQL Injection
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
CVE-2005-3914 EXPLOITDB text WRITEUP
Affcommerce - SQL Injection
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
CVE-2005-3914 EXPLOITDB text WRITEUP
Affcommerce - SQL Injection
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.
CVE-2005-4476 EXPLOITDB text WRITEUP
OpenEdit <4.0 - XSS
Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters.
CVE-2005-4576 EXPLOITDB text WRITEUP
Fatwire UpdateEngine <6.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.
CVE-2005-4306 EXPLOITDB text WRITEUP
SiteNet BBS <2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.
CVE-2005-4328 EXPLOITDB text WRITEUP
Webglimpse <2.14.1 - XSS
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
CVE-2005-4290 EXPLOITDB text WORKING POC
Soft4e Ecw-cart < 2.03 - XSS
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.
CVE-2005-4306 EXPLOITDB text WRITEUP
SiteNet BBS <2.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.