Exploitdb Exploits

2,809 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108723 EXPLOITDB perl VERIFIED
Joomla! Component JForJoomla! Jreservation 1.5 - 'pid' SQL Injection
by Chip d3 bi0s
EIP-2026-119320 EXPLOITDB perl VERIFIED
Xion Audio Player 1.0 121 - '.m3u' Remote Buffer Overflow (1)
by corelanc0d3r
EIP-2026-118181 EXPLOITDB perl VERIFIED
Xion Audio Player 1.0 121 - '.m3u' Local Buffer Overflow (2)
by Dragon Rider
EIP-2026-114772 EXPLOITDB perl VERIFIED
ProFTPd 1.3.0 (OpenSUSE) - 'mod_ctrls' Local Stack Overflow
by Michael Domberg
EIP-2026-107017 EXPLOITDB perl VERIFIED
EZsneezyCal CMS 95.1-95.2 - Remote File Inclusion
by kaMtiEz
CVE-2009-3694 EXPLOITDB perl VERIFIED
ezRecipe-Zee 91 - Path Traversal via cfg[prePath] Parameter
Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter.
by kaMtiEz
EIP-2026-108843 EXPLOITDB perl VERIFIED
Joomla! Component Recerca - SQL Injection
by Don Tukulesto
CVE-2009-0476 EXPLOITDB perl VERIFIED
MultiMedia Soft AdjMmsEng.dll <7.11.2.7 - Buffer Overflow
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as originally reported for Euphonics Audio Player 1.0. NOTE: some of these details are obtained from third party information.
by germaya_x
CVE-2009-3500 EXPLOITDB perl VERIFIED
BPowerHouse BPGames 1.0 - SQL Injection via cat_id or game_id Parameter
Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.
by OoN Boy
CVE-2009-3446 EXPLOITDB perl VERIFIED
com_mytube 1.0 Beta - SQL Injection via user_id Parameter
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.
by Chip d3 bi0s
CVE-2009-4659 EXPLOITDB perl VERIFIED
MP3-Cutter Ease Audio Cutter <1.20 - DoS
Unspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.20 allows user-assisted remote attackers to cause a denial of service (application crash) via a long string in a WAV file.
by zAx
CVE-2009-3316 EXPLOITDB perl VERIFIED
JReservation 1.0 and 1.5 - SQL Injection via pid Parameter
SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.
by Chip d3 bi0s
EIP-2026-108399 EXPLOITDB perl VERIFIED
Joomla! Component com_jlord_rss - 'id' Blind SQL Injection
by Chip d3 bi0s
CVE-2009-3449 EXPLOITDB perl VERIFIED
MP3 Collector 2.3 - Denial of Service via Long URL in M3U Playlist File
MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file.
by zAx
CVE-2009-4656 EXPLOITDB perl VERIFIED
E-Soft DJ Studio Pro <5.1.4.3.1 - Buffer Overflow
Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a playlist file (.pls) containing a long string. NOTE: some of these details are obtained from third party information.
by prodigy
EIP-2026-119208 EXPLOITDB perl VERIFIED
Techlogica HTTP Server 1.03 - Arbitrary File Disclosure
by ThE g0bL!N
CVE-2009-4107 EXPLOITDB perl VERIFIED
Invisible Browsing 5.0.52 - Buffer Overflow via Crafted .ibkey File
Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.
by PLATEN
CVE-2009-3663 EXPLOITDB perl VERIFIED
httpdx Web Server 1.4 - Remote Code Execution via Host Header Format String Specifiers
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header.
by Pankaj Kohli
CVE-2009-3336 EXPLOITDB perl VERIFIED
PHP Pro Bid - SQL Injection via auction_id Parameter
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.
by NoGe
CVE-2009-1071 EXPLOITDB perl VERIFIED
Icarus 2.0 - Stack-based Buffer Overflow via Crafted PGN File
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file.
by germaya_x
CVE-2009-3272 EXPLOITDB perl VERIFIED
Apple Safari - Denial of Service via JavaScript eval on Long String
Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences.
by Jeremy Brown
EIP-2026-117365 EXPLOITDB perl VERIFIED
jetAudio 7.1.9.4030 plus - vx(asx/wax/wvx) Universal Local Buffer Overflow (SEH)
by hack4love
CVE-2009-3201 EXPLOITDB perl VERIFIED
Media Player Classic 6.4.9 - Denial of Service via Malformed MIDI File Header
Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007-4940.
by PLATEN
CVE-2009-4775 EXPLOITDB perl VERIFIED
Ipswitch WS_FTP Professional 12 - Denial of Service via HTTP Response Status Code Format String
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.
by Jeremy Brown
CVE-2009-4628 EXPLOITDB perl VERIFIED
Joomla! com_tpdugg 1.1 - SQL Injection
SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.
by NoGe