Html Exploits

2,054 exploits tracked across all sources.

Sort: Activity Stars
CVE-2008-2841 EXPLOITDB html VERIFIED
Microsoft Internet Explorer < 2.8.7b - Code Injection
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.
by securfrog
EIP-2026-119315 EXPLOITDB html VERIFIED
XChat 2.8.7b - 'ircs://' URI Command Execution
by securfrog
CVE-2008-2910 EXPLOITDB html VERIFIED
Muvee Autoproducer - Memory Corruption
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting property value.
by Nine:Situations:Group
CVE-2008-2745 EXPLOITDB html VERIFIED
Black ICE Annotation Software - Memory Corruption
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows remote attackers to execute arbitrary code via a long parameter to the AnnoSaveToTiff method.
by shinnai
CVE-2008-2745 EXPLOITDB html VERIFIED
Black ICE Annotation Software - Memory Corruption
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows remote attackers to execute arbitrary code via a long parameter to the AnnoSaveToTiff method.
by shinnai
CVE-2008-2683 EXPLOITDB html VERIFIED
Black ICE Barcode SDK - Improper Input Validation
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, and the local filename in the second argument. NOTE: some of these details are obtained from third party information.
by shinnai
CVE-2008-2693 EXPLOITDB html VERIFIED
Black ICE Barcode SDK - Memory Corruption
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via a long first argument to the SetByteOrder method.
by shinnai
CVE-2008-2693 EXPLOITDB html VERIFIED
Black ICE Barcode SDK - Memory Corruption
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via a long first argument to the SetByteOrder method.
by shinnai
CVE-2008-2684 EXPLOITDB html VERIFIED
Blackice Black Ice Barcode SDK - Code Injection
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: some of these details are obtained from third party information.
by shinnai
CVE-2008-1770 EXPLOITDB html VERIFIED
Akamai Download Manager <2.2.3.6 - CRLF Injection
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.
by cocoruder
CVE-2008-2551 EXPLOITDB html VERIFIED
Icona Instant Messenger - Access Control
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."
by Nine:Situations:Group
CVE-2008-2650 EXPLOITDB html VERIFIED
Cmsimple - Path Traversal
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.
by irk4z
CVE-2008-2511 EXPLOITDB html VERIFIED
CA Internet Security Suite Plus 2008 - Path Traversal
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: some of these details are obtained from third party information.
by Nine:Situations:Group
EIP-2026-115019 EXPLOITDB html VERIFIED
CA Internet Security Suite - 'UmxEventCli.dll' ActiveX Control Arbitrary File Overwrite
by Nine:Situations:Group
CVE-2008-0955 EXPLOITDB html VERIFIED
Creative Software Autoupdate Engine - Memory Corruption
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value.
by BitKrush
CVE-2008-6619 EXPLOITDB html VERIFIED
Netlab Classsystem - Access Control
Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.
by Unohope
EIP-2026-100588 EXPLOITDB html VERIFIED
The Campus Request Repairs System 1.2 - 'sentout.asp' Unauthorized Access
by Unohope
CVE-2008-2419 EXPLOITDB html VERIFIED
Mozilla Firefox - Resource Management Error
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.
by 0x000000
CVE-2008-1767 EXPLOITDB html VERIFIED
libxslt <1.1.24 - Buffer Overflow
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
by Anthony de Almeida Lopes
CVE-2008-2349 EXPLOITDB html VERIFIED
Zomplog < 3.8.2 - Access Control
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
by ArxWolf
CVE-2008-2281 EXPLOITDB html VERIFIED
Internet Explorer <8.0b - XSS
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.
by Aviv Raff
CVE-2008-2283 EXPLOITDB html VERIFIED
Idautomation Aztec Barcode - Improper Input Validation
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.
by shinnai
CVE-2008-5217 EXPLOITDB html VERIFIED
txtCMS 0.3 - Path Traversal
Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
by cOndemned
EIP-2026-119016 EXPLOITDB html VERIFIED
Ourgame 'GLIEDown2.dll' ActiveX Control - Remote Code Execution
by anonymous
CVE-2008-2196 EXPLOITDB html VERIFIED
Lifetype - XSS
Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.
by Khashayar Fereidani