Exploitdb Exploits

1,269 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108505 EXPLOITDB php VERIFIED
Joomla! Component com_races - Blind SQL Injection
by DevilZ TM
EIP-2026-103628 EXPLOITDB php
PHP (Multiple Functions) - Local Denial of Service
by Yakir Wizman
CVE-2010-0397 EXPLOITDB php VERIFIED
Php - Denial of Service
The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.
by Auke van Slooten
CVE-2009-4018 EXPLOITDB php
PHP <5.2.11 & 5.3.x <5.3.1 - Command Injection
The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.
by Hamid Ebadi
CVE-2010-1349 EXPLOITDB php
Opera <10.50 - RCE
Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.
by Marcin Ressel
EIP-2026-108433 EXPLOITDB php
Joomla! Component com_liveticker - Blind SQL Injection
by snakespc
EIP-2026-108473 EXPLOITDB php VERIFIED
Joomla! Component com_paxgallery - Blind Injection
by snakespc
EIP-2026-103572 EXPLOITDB php VERIFIED
Mozilla Firefox 3.6 - Denial of Service (2)
by Ale46
EIP-2026-108411 EXPLOITDB php VERIFIED
Joomla! Component com_Joomlaconnect_be - Blind Injection
by snakespc
EIP-2026-108372 EXPLOITDB php VERIFIED
Joomla! Component com_ice - Blind SQL Injection
by snakespc
CVE-2010-1130 EXPLOITDB php VERIFIED
PHP <5.2.13, 5.3.1 - Info Disclosure
session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).
by Grzegorz Stachowiak
EIP-2026-105261 EXPLOITDB php VERIFIED
ASCET Interactive Huski CMS - 'i' Local File Inclusion
by Wireghoul
EIP-2026-108172 EXPLOITDB php
Joomla! 1.5.12 - read/exec Remote files
by Nikoal Petrov
EIP-2026-108171 EXPLOITDB php
Joomla! 1.5.12 - Connect Back
by Nikola Petrov
CVE-2010-1073 EXPLOITDB php
Joomla! - SQL Injection
SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.
by FL0RiX
EIP-2026-108278 EXPLOITDB php VERIFIED
Joomla! Component com_bfsurvey_pro - 'catid' Blind SQL Injection
by FL0RiX
EIP-2026-108268 EXPLOITDB php
Joomla! Component com_aprice - Blind SQL Injection
by FL0RiX
EIP-2026-105425 EXPLOITDB php
bbScript 1.1.2.1 - 'id' Blind SQL Injection
by cOndemned
EIP-2026-107248 EXPLOITDB php VERIFIED
FreeWebShop 2.2.9 R2 - Multiple Remote Vulnerabilities
by Akita Software Security
CVE-2007-4652 EXPLOITDB php VERIFIED
PHP <5.2.4 - Auth Bypass
The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.
by Maksymilian Arciemowicz
CVE-2009-4142 EXPLOITDB php VERIFIED
PHP <5.2.12 - XSS
The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.
CVE-2009-4142 EXPLOITDB php VERIFIED
PHP <5.2.12 - XSS
The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.
EIP-2026-108410 EXPLOITDB php
Joomla! Component com_joomgallery 1.5.x - &func Incorrect Flood Filter
by Jbyte
CVE-2009-4195 EXPLOITDB php VERIFIED
Adobe Illustrator <14.0.0 - Buffer Overflow
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. NOTE: some of these details are obtained from third party information.
by pyrokinesis
EIP-2026-113133 EXPLOITDB php VERIFIED
Vivid Ads Shopping Cart - 'prodid' SQL Injection
by Yakir Wizman