Html Exploits

2,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-109567 EXPLOITDB html VERIFIED
Monstra CMS 1.2.1 - Multiple HTML Injection Vulnerabilities
by LiquidWorm
EIP-2026-112951 EXPLOITDB html
VamCart 0.9 - Cross-Site Request Forgery
by DaOne
EIP-2026-110282 EXPLOITDB html
OpenDocMan 1.2.6.1 - Cross-Site Request Forgery (Password Change)
by Shai rod
EIP-2026-110570 EXPLOITDB html VERIFIED
PG Portal Pro - Cross-Site Request Forgery
by Noxious
EIP-2026-105934 EXPLOITDB html VERIFIED
Clipbucket 2.5 - Cross-Site Request Forgery
by DaOne
EIP-2026-108041 EXPLOITDB html VERIFIED
Jaow CMS 2.3 - Cross-Site Request Forgery
by DaOne
EIP-2026-103557 EXPLOITDB html VERIFIED
Mozilla Firefox - Remote Denial of Service
by Jean Pascal Pereira
EIP-2026-113777 EXPLOITDB html VERIFIED
WordPress Plugin G-Lock Double Opt-in Manager - SQL Injection
by BEASTIAN
EIP-2026-118305 EXPLOITDB html VERIFIED
Barcodewiz 'Barcodewiz.dll' ActiveX Control - 'Barcode' Method Remote Buffer Overflow
by coolkaveh
EIP-2026-110002 EXPLOITDB html VERIFIED
Nwahy Articles 2.2 - Cross-Site Request Forgery (Add Admin)
by DaOne
EIP-2026-103416 EXPLOITDB html VERIFIED
Arora Browser - Remote Denial of Service
by t3rm!n4t0r
CVE-2012-4000 EXPLOITDB html VERIFIED
FCKeditor < 2.6.7 - Cross-Site Scripting via textinputs Array Parameter
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.
by Emilio Pinna
EIP-2026-112389 EXPLOITDB html VERIFIED
SPIP 2.x - Multiple Cross-Site Scripting Vulnerabilities
by anonymous
EIP-2026-108673 EXPLOITDB html VERIFIED
Joomla! Component IDoEditor - 'image.php' Arbitrary File Upload
by Sammy FORGIT
CVE-2012-2959 EXPLOITDB html VERIFIED
BMC Identity Management Suite 7.5.00.103 - CSRF
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.
by Travis Lee
EIP-2026-112708 EXPLOITDB html VERIFIED
TinyCMS 1.3 - Arbitrary File Upload / Cross-Site Request Forgery
by KedAns-Dz
EIP-2026-104853 EXPLOITDB html
4PSA VoIPNow Professional 2.5.3 - Multiple Vulnerabilities
by Aboud-el
CVE-2012-0985 EXPLOITDB html
Sony VAIO PC Wireless LAN Wizard 1.0-4.11 - Buffer Overflow
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.
by High-Tech Bridge SA
CVE-2012-6046 EXPLOITDB html VERIFIED
PHP Enter - Remote Code Injection via admin/banners.php code Parameter
Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.
by L3b-r1'z
CVE-2012-4250 EXPLOITDB html
Samsung NET-i viewer 1.37 - Remote Code Execution via RequestScreenOptimization Function
Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrary code via a long string in the first argument.
by blake
EIP-2026-105172 EXPLOITDB html VERIFIED
Anchor CMS 0.6-14-ga85d0a0 - 'id' Multiple HTML Injection Vulnerabilities
by Gjoko Krstic
EIP-2026-105460 EXPLOITDB html VERIFIED
BGS CMS 2.2.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by LiquidWorm
CVE-2012-1665 EXPLOITDB html VERIFIED
osCMax < 2.5.1 - SQL Injection via Admin Panel Parameters
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.
by High-Tech Bridge SA
CVE-2012-4877 EXPLOITDB html VERIFIED
Flatnux < 2011-08-09-2 - Cross-Site Request Forgery in controlcenter.php
Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts.
by Vulnerability Laboratory
EIP-2026-118277 EXPLOITDB html VERIFIED
Apple Safari 5.1.5 For Windows - 'window.open()' URI Spoofing
by Lostmon