Exploitdb Exploits
2,814 exploits tracked across all sources.
TYPSoft FTP Server 1.10 - Multiple Denial of Service Vulnerabilities
by Balazs Makany
4Images 1.7.6-9 - Cross-Site Request Forgery / PHP Code Injection
by Or4nG.M4N
UltraPlayer 2.112 - '.avi' File Denial of Service
by KedAns-Dz
php iReport 1.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web script or HTML via the message parameter to (1) messages_viewer.php, (2) home.php, or (3) history.php.
by Or4nG.M4N
IDevSpot iSupport <1 - CSRF
Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.
by Or4nG.M4N
Blade API Monitor 3.6.9.2 - Unicode Stack Buffer Overflow
by FullMetalFouad
Enigma2 Webinterface <1.5 - Path Traversal
Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
by Todor Donev
Enigma2 Webinterface <1.7.0 - Path Traversal
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter.
by Todor Donev
Mjsware M-player - Improper Input Validation
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
by JaMbA
AirTies Air 4450 <1.1.2.18 - DoS
AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.
by rigan
IpTools <0.1.4 - Buffer Overflow
Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service (crash) via a long string to TCP port 23.
by demonalex
VLC media player <1.1.11 - DoS
VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.
by Fabi@habsec
Tomatosoft Free Mp3 Player - Improper Input Validation
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.
by JaMbA
Mpdf < 5.3 - Path Traversal
Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
by ZadYree
Zftpserver Suite - Path Traversal
Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a crafted RMD (aka rmdir) command.
by Stefan Schurtz
D-Link DNS-320 ShareCenter - Remote Reboot/Shutdown/Reset (Denial of Service)
by rigan
Bugbear Flatout - Memory Corruption
Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file.
by Silent_Dream
PHP-Nuke <8.1.0.3.5b - SQL Injection
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.
by Dante90
Soda PDF Professional 1.2.155 - '.pdf' / '.WWF' File Handling Denial of Service
by LiquidWorm
COMTREND CT-5624 Router - Root/Support Password Disclosure/Change
by Todor Donev
OpenPAM <r478 - Privilege Escalation
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.
by IKCE
Dream-multimedia-tv Dreambox Dm800 HD SE Firmware - Path Traversal
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file parameter.
by Todor Donev
BlueZone Desktop - Multiple Malformed Files Local Denial of Service Vulnerabilities
by Silent_Dream
BlueZone - '.zft' File Local Denial of Service
by Iolo Morganwg
By Source