Exploitdb Exploits

2,809 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-5261 EXPLOITDB perl VERIFIED
MultiCart 1.0 - SQL Injection via catid or ddlCategory Parameter
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.
by k1tk4t
CVE-2007-5256 EXPLOITDB perl VERIFIED
FSD 2.052 d9 and earlier - Remote Code Execution via Long HELP Command
Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote attackers to execute arbitrary code via a long HELP command on TCP port 3010 to the sysuser::exechelp function in sysuser.cc and (2) remote authenticated users to execute arbitrary code via long commands on TCP port 6809 to the servinterface::sendmulticast function in servinterface.cc, as demonstrated by a PIcallsign command.
by Luigi Auriemma
CVE-2007-5222 EXPLOITDB perl VERIFIED
MAXdev MDPro 1.0.76 - SQL Injection via Referer Header
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.
by undefined1_
CVE-2007-5222 EXPLOITDB perl VERIFIED
MAXdev MDPro 1.0.76 - SQL Injection via Referer Header
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.
by unidentified1_ is
CVE-2007-5063 EXPLOITDB perl VERIFIED
Adam Scheinberg Flip <= 3.0 - Unauthenticated Sensitive Information Exposure via Direct Request
Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt.
by undefined1_
CVE-2007-5062 EXPLOITDB perl VERIFIED
Adam Scheinberg Flip < 3.0 - Unauthenticated Administrative Account Creation via account.php un Parameter
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action.
by undefined1_
CVE-2007-5018 EXPLOITDB perl VERIFIED
Mercury/32 4.52 - Authenticated Stack-Based Buffer Overflow via IMAP SEARCH ON Command
Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
by void
CVE-2007-5016 EXPLOITDB perl VERIFIED
OneCMS 2.4 - SQL Injection via userreviews.php abc Parameter
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.
by str0ke
CVE-2007-4984 EXPLOITDB perl VERIFIED
Ktauber StylesDemo - SQL Injection via s Parameter
SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.
by nexen
CVE-2007-5036 EXPLOITDB perl VERIFIED
AirDefense Airsensor M520 4.3.1.1 and 4.4.1.4 - Authenticated Denial of Service via Crafted HTTPS Query String
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."
by Alex Hernandez
CVE-2007-4956 EXPLOITDB perl VERIFIED
KwsPHP 1.0 - SQL Injection via pseudo Parameter
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
by s4mi
CVE-2007-4956 EXPLOITDB perl VERIFIED
KwsPHP 1.0 - SQL Injection via pseudo Parameter
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
by s4mi
CVE-2007-4956 EXPLOITDB perl VERIFIED
KwsPHP 1.0 - SQL Injection via pseudo Parameter
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
by s4mi
CVE-2007-4919 EXPLOITDB perl VERIFIED
JBlog 1.0 - SQL Injection via id Parameter
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.
by s4mi
CVE-2007-4725 EXPLOITDB perl VERIFIED
7-zip < 4.42 - Stack Consumption via Long Filename in Archive
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.
by miyy3t
CVE-2007-4776 EXPLOITDB perl VERIFIED
Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 - Buffer Overflow via Long Reference Line in VBP File
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are limited usage scenarios under which this would be a vulnerability.
by Koshi
CVE-2007-4726 EXPLOITDB perl VERIFIED
weboddity 0.09b - Path Traversal via URI
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
by Katatafish
CVE-2007-4653 EXPLOITDB perl VERIFIED
phpBB Links MOD < 1.2.2 - SQL Injection via Start Parameter
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.
by Don
CVE-2007-4736 EXPLOITDB perl VERIFIED
CartKeeper CKGold Shopping Cart 2.0 - SQL Injection via category_id Parameter
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
by k1tk4t
CVE-2007-6113 EXPLOITDB perl VERIFIED
Wireshark 0.10.12-0.99.6 - Denial of Service via DNP3 Dissector Integer Signedness Error
Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.
by Beyond Security
CVE-2007-4627 EXPLOITDB perl VERIFIED
ABC eStore 3.0 - SQL Injection via cat_id Parameter
SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
by k1tk4t
CVE-2007-4604 EXPLOITDB perl VERIFIED
DL PayCart 1.01 - SQL Injection via ItemID Parameter
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
by irvian
EIP-2026-101095 EXPLOITDB perl VERIFIED
Thomson SpeedTouch 2030 - SIP Empty Message Remote Denial of Service
by Humberto J. Abdelnur
CVE-2007-4220 EXPLOITDB perl VERIFIED
Motorola Timbuktu Pro <8.6.5 - Path Traversal
Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a .. (dot dot) in a Send request, probably related to the (1) Send and (2) Exchange services.
by titon
CVE-2007-2930 EXPLOITDB perl VERIFIED
ISC BIND <8.4.7-P1 - Info Disclosure
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.
by Amit Klein