Exploitdb Exploits
2,809 exploits tracked across all sources.
SGI InfoSearch < - Command Injection
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.
by rpc
HP OpenView OmniBack II 2.55 - Denial of Service via Port 5555 Connection Flood
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.
by Jon Hittner
wwwthreads - SQL Injection via Numeric Data or Table Names
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.
by rain forest puppy
SolutionScripts Home Free - Path Traversal
search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.
by k0ad k1d
WebWho+ - Remote Command Execution via TLD Parameter
WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
by loophole
Mdaemon 3.1.1 - Heap Overflow via Long URL
Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.
by Ussr Labs
Qpopper 3.0 - Unauthenticated Buffer Overflow via AUTH Command
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
by Synnergy Networks
Trend Micro InterScan VirusWall 3.23 and 3.3 - Remote Code Execution via Long HELO Command
A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.
by Alain Thivillon & Stephane Aubert
WFTPD - Buffer Overflow via Nested MKD and CWD Commands
Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
by Alberto Soli
IBM WebSphere ikeyman - Weak Encryption for SSL Key Database Password
IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.
by Ben Laurie
Mediahouse Statistics Server - Remote Code Execution via Buffer Overflow
Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
by Per Bergehed
IBM AIX - Buffer Overflow in libc ftpd
Buffer overflow in AIX ftpd in the libc library.
by Gerrie
SSH Agent - Symlink Following via UNIX Domain Socket
The SSH authentication agent follows symlinks via a UNIX domain socket.
by Tymm Twillman
WebTrends Enterprise Reporting Server 1.5 - Negative Content Length Denial of Service
by rpc
Microsoft Data Access Components - Remote Code Execution via RDS DataFactory
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
by rain forest puppy
Internet Information Server 4.0 - Denial of Service via Malformed .HTR/.IDC/.STM Request
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
by eEye Digital Security Team
TYPSoft FTP Server <0.78 - Buffer Overflow
Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.
by dethy
Microsoft IIS 4.0 / Microsoft JET 3.5/3.5.1 Database Engine - VBA
by J. Abreu Junior
UnixWare - Arbitrary File Write via Symlink Attack
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
by Brock Tellier
Check Point Software Firewall-1 3.0/1 4.0 - Session Agent Impersonation
by Andrew Danforth
Apache HTTP Server - Denial of Service via Large Number of MIME Headers
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
by L.Facq
textcounter.pl - Remote Command Execution via Shell Metacharacters
The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.
by Doru Petrescu
Ascend MAX and Pipeline Routers - Denial of Service via Malformed Packet to Discard Port
Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.
by Rootshell
By Source