Exploitdb Exploits

2,809 exploits tracked across all sources.

Sort: Activity Stars
CVE-2013-3522 EXPLOITDB perl VERIFIED
vBulletin 5.0.0 Beta 11 and earlier - Authenticated SQL Injection via nodeid Parameter
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.
by Orestis Kourides
EIP-2026-102030 EXPLOITDB perl
StarVedia IPCamera IC502w IC502w+ v020313 - 'Username'/Password Disclosure
by Todor Donev
EIP-2026-105619 EXPLOITDB perl VERIFIED
Brewthology 0.1 - SQL Injection
by cr4wl3r
EIP-2026-115518 EXPLOITDB perl VERIFIED
KMPlayer - Denial of Service
by Jigsaw
CVE-2013-1359 EXPLOITDB CRITICAL perl
DELL SonicWALL Analyzer 7.0, GMS 4.1-7.0, UMA 5.1-7.0, ViewPoint 4.1-6.0 - Authentication Bypass
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.
by Nikolas Sotiriu
CVSS 9.8
CVE-2012-5627 EXPLOITDB perl VERIFIED
Oracle MySQL 5.5.0-5.5.28 & MariaDB 5.2.0-5.2.13 - Brute Force via Insufficient Salt Rotation
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
by kingcope
CVE-2012-5615 EXPLOITDB perl VERIFIED
Oracle MySQL <5.5.38 & MariaDB <5.5.28a - Info Disclosure
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.
by kingcope
CVE-2012-5613 EXPLOITDB perl VERIFIED
MySQL <5.5.19 & MariaDB <5.5.28a - Privilege Escalation
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
by kingcope
CVE-2012-5611 EXPLOITDB perl
Oracle MySQL <5.5.28 & MariaDB <5.5.28a - RCE
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.
by kingcope
CVE-2012-5612 EXPLOITDB perl
Oracle MySQL <5.5.29 - Buffer Overflow
Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.
by kingcope
CVE-2012-4409 EXPLOITDB perl VERIFIED
mcrypt < 2.6.8 - Stack-Based Buffer Overflow via Encrypted File Header
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption.
by Tosh
EIP-2026-103543 EXPLOITDB perl VERIFIED
Media Player Classic (MPC) 1.5 - WebServer Request Handling Remote Denial of Service
by X-Cisadane
EIP-2026-102870 EXPLOITDB perl
HT Editor 2.0.20 - Local Buffer Overflow (ROP)
by ZadYree
EIP-2026-102076 EXPLOITDB perl VERIFIED
TP-Link TL-WR841N Router - Local File Inclusion
by Matan Azugi
EIP-2026-115798 EXPLOITDB perl VERIFIED
Microsoft Windows Help Program - 'WinHlp32.exe' Crash (PoC)
by coolkaveh
EIP-2026-115758 EXPLOITDB perl VERIFIED
Microsoft Paint 5.1 - '.bmp' Denial of Service
by coolkaveh
EIP-2026-115519 EXPLOITDB perl VERIFIED
KMPlayer 3.0.0.1440 - '.avi' File Local Denial of Service
by Am!r
EIP-2026-114918 EXPLOITDB perl VERIFIED
Apple QuickTime Player 7.7.2 - Crash (PoC)
by coolkaveh
EIP-2026-116166 EXPLOITDB perl VERIFIED
RealPlayer 15.0.6.14.3gp - Crash (PoC)
by coolkaveh
EIP-2026-114865 EXPLOITDB perl VERIFIED
Adobe Reader 10.1.4 - Crash (PoC)
by coolkaveh
EIP-2026-108427 EXPLOITDB perl VERIFIED
Joomla! Component com_kunena - 'search' SQL Injection
by D35m0nd142
CVE-2012-6568 EXPLOITDB perl
Huawei UTPS 1.0 - Buffer Overflow via IDS_PLUGIN_NAME in Plugin Configuration File
Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a plug-in configuration file.
by Dark-Puzzle
EIP-2026-115804 EXPLOITDB perl VERIFIED
Microsoft Windows Media Player 10 - '.avi' Integer Division By Zero Crash (PoC)
by Dark-Puzzle
CVE-2012-5470 EXPLOITDB perl VERIFIED
VLC media player 2.0.3 - Denial of Service via Crafted PNG File
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.
by Jean Pascal Pereira
CVE-2012-5672 EXPLOITDB perl VERIFIED
Microsoft Excel and Excel Viewer - Denial of Service via Crafted Spreadsheet File
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
by Jean Pascal Pereira