Html Exploits

2,054 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110381 EXPLOITDB html VERIFIED
osCommerce 3.0a5 - Local File Inclusion / HTML Injection
by Jordi Chancel
EIP-2026-116530 EXPLOITDB html VERIFIED
Webmoney Advisor - ActiveX Remote Denial of Service
by Go0o$E
EIP-2026-114921 EXPLOITDB html VERIFIED
Apple Safari 4.0.3/4.0.4 - Stack Exhaustion
by Fredrik Nordberg Almroth
CVE-2010-2039 EXPLOITDB html VERIFIED
Gpeasy Cms < 1.6.2 - CSRF
Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.
by Giuseppe 'giudinvx' D'Inverno
CVE-2010-0050 EXPLOITDB HIGH html VERIFIED
Apple Safari < 4.0.5 - Use After Free
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.
by Dr_IDE
CVSS 8.8
EIP-2026-103712 EXPLOITDB html VERIFIED
WebKit 532.5 - Stack Exhaustion
by Mathias Karlsson
CVE-2006-4584 EXPLOITDB html VERIFIED
Tr Forum 2.0 - Auth Bypass
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.
by EL-KAHINA
EIP-2026-118645 EXPLOITDB html
HP Digital Imaging - 'hpodio08.dll' Insecure Method
by ThE g0bL!N
CVE-2010-1033 EXPLOITDB html VERIFIED
HP Operations Manager <8.16 - RCE
Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll.
by mr_me
EIP-2026-118738 EXPLOITDB html VERIFIED
Magneto Net Resource ActiveX 4.0.0.5 - 'NetShareEnum' Universal
by dookie
EIP-2026-118737 EXPLOITDB html VERIFIED
Magneto Net Resource ActiveX 4.0.0.5 - 'NetFileClose' Universal
by dookie
EIP-2026-118736 EXPLOITDB html VERIFIED
Magneto Net Resource ActiveX 4.0.0.5 - 'NetConnectionEnum' Universal
by dookie
EIP-2026-118740 EXPLOITDB html VERIFIED
MagnetoSoft SNTP 4.0.0.7 - ActiveX SntpGetReply Buffer Overflow
by s4squatch
EIP-2026-118739 EXPLOITDB html VERIFIED
MagnetoSoft ICMP 4.0.0.18 - ActiveX AddDestinationEntry Buffer Overflow
by s4squatch
EIP-2026-115579 EXPLOITDB html VERIFIED
MagnetoSoft SNTP 4.0.0.7 - ActiveX SntpSendRequest Crash (PoC)
by s4squatch
EIP-2026-115578 EXPLOITDB html VERIFIED
MagnetoSoft NetworkResources 4.0.0.5 - ActiveX NetShareEnum Overwrite (SEH) (PoC)
by s4squatch
EIP-2026-115577 EXPLOITDB html VERIFIED
MagnetoSoft NetworkResources 4.0.0.5 - ActiveX NetSessionDel (PoC)
by s4squatch
EIP-2026-115576 EXPLOITDB html VERIFIED
MagnetoSoft NetworkResources 4.0.0.5 - ActiveX NetFileClose Overwrite (SEH) (PoC)
by s4squatch
EIP-2026-115575 EXPLOITDB html VERIFIED
MagnetoSoft NetworkResources - ActiveX NetConnectionEnum Overwrite (SEH) (PoC)
by s4squatch
EIP-2026-115574 EXPLOITDB html VERIFIED
MagnetoSoft DNS 4.0.0.9 - ActiveX DNSLookupHostWithServer (PoC)
by s4squatch
CVE-2010-1528 EXPLOITDB html VERIFIED
Uiga Proxy - RCE
PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
by ITSecTeam
EIP-2026-112804 EXPLOITDB html
ttCMS 5.0 - Remote File Inclusion
by ITSecTeam
EIP-2026-111485 EXPLOITDB html
Prediction League 0.3.8 - Cross-Site Request Forgery (Add Admin)
by indoushka
CVE-2010-1351 EXPLOITDB html VERIFIED
Nodesforum <1.045 - RCE
Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to erase_user_data.php and the (2) _nodesforum_code_path parameter to pre_output.php. NOTE: some of these details are obtained from third party information.
by ITSecTeam
EIP-2026-109647 EXPLOITDB html
MunkyScripts Simple Gallery - SQL Injection
by ITSecTeam