Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105725 EXPLOITDB php
cardinalCMS 1.2 - 'FCKeditor' Arbitrary File Upload
by Ma3sTr0-Dz
EIP-2026-107935 EXPLOITDB php
Invision Power Board 3.0.1 - SQL Injection
by Cryptovirus
EIP-2026-115162 EXPLOITDB php VERIFIED
Dolphin 2.0 - '.elf' Local Denial of Service
by Yakir Wizman
CVE-2004-1315 EXPLOITDB php
phpBB 2.x <2.0.11 - RCE
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.
by Michael Brooks
EIP-2026-116889 EXPLOITDB php VERIFIED
Beyond Compare 3.0.13 b9599 - '.zip' Local Stack Buffer Overflow
by mr_me
EIP-2026-109030 EXPLOITDB php VERIFIED
Knowledgeroot (fckeditor) - Arbitrary File Upload
by eidelweiss
CVE-2010-1866 EXPLOITDB CRITICAL php VERIFIED
Php < 5.3.2 - Integer Overflow
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.
by Stefan Esser
CVSS 9.8
EIP-2026-111412 EXPLOITDB php VERIFIED
Portaneo Portal 2.2.3 - Arbitrary File Upload
by eidelweiss
EIP-2026-117116 EXPLOITDB php VERIFIED
Easyzip 2000 3.5 - '.zip' Local Stack Buffer Overflow
by mr_me
EIP-2026-111040 EXPLOITDB php VERIFIED
phpegasus 0.1.2 - 'FCKeditor' Arbitrary File Upload
by eidelweiss
EIP-2026-112256 EXPLOITDB php VERIFIED
SmodCMS 4.07 (fckeditor) - Arbitrary File Upload
by eidelweiss
EIP-2026-114656 EXPLOITDB php
Zyke CMS 1.1 - Authentication Bypass
by Giuseppe 'giudinvx' D'Inverno
EIP-2026-104661 EXPLOITDB php VERIFIED
PHP 5.3.x - Denial of Service
by ITSecTeam
EIP-2026-105699 EXPLOITDB php VERIFIED
Camiro-CMS_beta-0.1 - 'FCKeditor' Arbitrary File Upload
by eidelweiss
EIP-2026-117770 EXPLOITDB php VERIFIED
PHP 6.0 Dev - 'str_transliterate()' Local Buffer Overflow (NX + ASLR Bypass)
by ryujin
EIP-2026-114415 EXPLOITDB php VERIFIED
xBtiTracker - SQL Injection
by InATeam
CVE-2010-5300 EXPLOITDB php VERIFIED
Jzip <2.0.0.132900 - Buffer Overflow
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.
by mr_me
EIP-2026-117769 EXPLOITDB php VERIFIED
PHP 6.0 Dev - 'str_transliterate()' Local Buffer Overflow
by Yakir Wizman
EIP-2026-118200 EXPLOITDB php VERIFIED
Zip Unzip 6.0 - '.zip' Local Stack Buffer Overflow
by mr_me
EIP-2026-115171 EXPLOITDB php VERIFIED
Dualis 20.4 - '.bin' Local Denial of Service
by Yakir Wizman
CVE-2011-5165 EXPLOITDB php VERIFIED
Cleanersoft Free Mp3 CD Ripper < 2.6 - Memory Corruption
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.
by mr_me
EIP-2026-108971 EXPLOITDB php
Kasseler CMS 1.4.x lite Module Jokes - SQL Injection
by Sc0rpi0n
CVE-2010-1343 EXPLOITDB php VERIFIED
SiteX 0.7.4 beta - SQL Injection
SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter.
by Sc0rpi0n
CVE-2010-1131 EXPLOITDB php VERIFIED
JavaScriptCore.dll - DoS
JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the <object> substring.
by 3lkt3F0k4
CVE-2010-0966 EXPLOITDB php VERIFIED
deV!L`z Clanportal 1.5.2 - Code Injection
PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.
by cr4wl3r