Exploitdb Exploits

2,814 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-2127 EXPLOITDB perl VERIFIED
ATI Catalyst Driver - Memory Corruption
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
by anonymous
CVE-2005-3533 EXPLOITDB perl VERIFIED
Osh < 1.7.14 - Buffer Overflow
Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.
by Charles Stevenson
CVE-2005-2581 EXPLOITDB perl VERIFIED
Grandstream Budgetone 101 < 1.0.6.7 - Denial of Service
Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060.
by Pierre Kroma
EIP-2026-114853 EXPLOITDB perl VERIFIED
Acunetix HTTP Sniffer - Denial of Service
by basher13
CVE-2005-2468 EXPLOITDB perl VERIFIED
Mysql Eventum - SQL Injection
Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.
by GulfTech Security
CVE-2005-1255 EXPLOITDB perl VERIFIED
IMail <8.2 - Buffer Overflow
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.
by kingcope
CVE-2005-2472 EXPLOITDB perl VERIFIED
Netcplus Businessmail - Buffer Overflow
Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.
by Reed Arvin
CVE-2005-2426 EXPLOITDB perl VERIFIED
Ftpshell Server - Denial of Service
FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.
by Reed Arvin
CVE-2005-2420 EXPLOITDB perl VERIFIED
FtpLocate 2.02 - RCE
flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.
by newbug
EIP-2026-118698 EXPLOITDB perl VERIFIED
Intruder Client 1.00 - Remote Command Execution / Denial of Service
by basher13
EIP-2026-114892 EXPLOITDB perl VERIFIED
Alt-N MDaemon 8.0 - IMAP Server CREATE Remote Buffer Overflow (PoC)
by kcope
EIP-2026-110223 EXPLOITDB perl VERIFIED
Open Bulletin Board 1.0.5 - SQL Injection
by RusH
EIP-2026-119148 EXPLOITDB perl VERIFIED
Small HTTP Server 3.05.28 - Arbitrary Data Execution
by basher13
CVE-2005-2305 EXPLOITDB perl VERIFIED
DG Remote Control Server - Buffer Overflow
DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.
by basher13
EIP-2026-115175 EXPLOITDB perl VERIFIED
DzSoft PHP Editor 3.1.2.8 - Denial of Service
by basher13
EIP-2026-118302 EXPLOITDB perl VERIFIED
Baby Web Server 2.6.2 - Command Validation
by basher13
EIP-2026-116177 EXPLOITDB perl VERIFIED
Remote File Explorer 1.0 - Denial of Service
by basher13
EIP-2026-114898 EXPLOITDB perl VERIFIED
AnalogX SimpleServer:WWW 1.05 - Denial of Service
by Qnix
EIP-2026-101205 EXPLOITDB perl VERIFIED
Cisco VoIP Phone CP-7940 3.x - Spoofed SIP Status Message Handling
by DrFrancky
EIP-2026-100794 EXPLOITDB perl VERIFIED
eRoom 6.0 PlugIn - Insecure File Download Handling
by c0ntex
CVE-2005-2106 EXPLOITDB perl VERIFIED
Drupal <4.5.4-4.6.2 - RCE
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.
by dab
CVE-2005-2113 EXPLOITDB perl VERIFIED
Xoops - SQL Injection
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.
by RusH
CVE-2005-1921 EXPLOITDB perl VERIFIED
PHP Xml Rpc < 1.3.0 - Code Injection
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
by Mike Rifone
CVE-2005-1921 EXPLOITDB perl VERIFIED
PHP Xml Rpc < 1.3.0 - Code Injection
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
by dukenn
EIP-2026-110948 EXPLOITDB perl VERIFIED
phpBB 2.0.15 - 'highlight' Database Authentication Details
by SecureD