Html Exploits
2,076 exploits tracked across all sources.
Enthrallweb eClassifieds - Auth Bypass
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
by ajann
RealPlayer - Denial of Service via RealPlayer.Initialize Method
A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer crash) by invoking the RealPlayer.Initialize method with certain arguments.
by shinnai
KDE libkhtml < 4.2.0 - Denial of Service via Malformed HTML Tags
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.
by Federico L. Bossi Bonin
Microsoft Office Outlook Recipient ActiveX - DoS
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
by shinnai
Microsoft Office Outlook Recipient ActiveX - DoS
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
by shinnai
Knusperleicht ShoutBox 2.6 - Cross-Site Scripting via sbNick or sbKommentar Parameter
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
by IMHOT3B
Bandwebsite 1.5 - Unauthenticated Administrative Account Creation via Direct Request
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1.
by H0tTurk-
Microsoft Internet Explorer 6.0.2900.2180 - DoS
Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.
by xiam.core
Metyus Okul Yonetim Sistemi 1.0 - SQL Injection
SQL injection vulnerability in uye_giris_islem.asp in Metyus Okul Yonetim Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) kullanici_ismi and (2) sifre parameters.
by ShaFuck31
Aspee/Dogantepe Ziyaretci Defteri - SQL Injection
Multiple SQL injection vulnerabilities in giris.asp in Aspee and Dogantepe Ziyaretci Defteri allow remote attackers to execute arbitrary SQL commands via the (1) kullanici or (2) parola parameter.
by ShaFuq31
Acer Notebook LunchApp.APlunch - RCE
Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.
by Tan Chew Keong
Links/Elinks <1.00pre12-0.9.2 - RCE
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
by Teemu Salmela
Adobe Acrobat Reader 7.0-7.0.8 - Denial of Service and Possible Remote Code Execution via Long LoadFile Argument
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.
by Michal Bucko
WinZip 10.0 Build 6667 - Buffer Overflow
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.
by prdelka
macOS 10.4 - Denial of Service via JavaScript Regular Expression exec Method
Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression.
by jbh_cg
Links/Elinks <1.00pre12-0.9.2 - RCE
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
by Teemu Salmela
Online Event Registration 2.0 - 'save_profile.asp' Pass Change
by ajann
Microsoft XML Core Services 4.0 - RCE
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
by ~Fyodor
Microsoft XML Core Services 4.0 - RCE
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
by anonymous
BlooMooWeb 1.0.9 - ActiveX Control Multiple Vulnerabilities
by maxgipeh
Firefox 1.5.0.7 and 2.0 and Seamonkey 1.1b - Denial of Service via DocType Node Range Manipulation
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.
by Gotfault Security
Microsoft Internet Explorer 6 - Code Execution (2)
by Michal Bucko
Microsoft Internet Explorer 6 - Code Execution (1)
by Michal Bucko
E-Annu 1.0 - SQL Injection via Login Parameter
SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: some of these details are obtained from third party information.
by ajann
MiraksGalerie 2.62 - 'pcltar.lib.php' Remote File Inclusion
by ajann
By Source