Exploitdb Exploits

4,759 exploits tracked across all sources.

Sort: Activity Stars
CVE-2014-2022 EXPLOITDB python
vBulletin < 4.2.2 - Authenticated SQL Injection via XMLRPC API conceptid Argument
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.
by tintinweb
CVE-2014-7910 EXPLOITDB python VERIFIED
Google Chrome < 39.0.2171.65 - Denial of Service or Other Impact
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
by Phil Blank
CVE-2014-6278 EXPLOITDB HIGH python VERIFIED
GNU Bash through 4.3 bash43-026 - Remote Code Execution via Environment Variable Function Parsing
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
by Federico Galatolo
CVSS 8.8
CVE-2014-5289 EXPLOITDB CRITICAL python VERIFIED
Senkas Kolibri 2.0 - Remote Code Execution via Long URI in POST Request
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.
by tekwizz123
CVSS 9.8
CVE-2014-7910 EXPLOITDB python
Google Chrome < 39.0.2171.65 - Denial of Service or Other Impact
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
by @0x00string
CVE-2014-7910 EXPLOITDB python VERIFIED
Google Chrome < 39.0.2171.65 - Denial of Service or Other Impact
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
by Claudio Viviani
CVE-2014-7187 EXPLOITDB python VERIFIED
GNU Bash through 4.3 bash43-026 - Denial of Service via Deeply Nested For Loops
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.
by fdiskyou
EIP-2026-116582 EXPLOITDB python
WS10 Data Server - SCADA Overflow (PoC)
by Pedro Sánchez
EIP-2026-108434 EXPLOITDB python
Joomla! Component com_macgallery 1.5 - Arbitrary File Download
by Claudio Viviani
EIP-2026-108344 EXPLOITDB python
Joomla! Component com_facegallery 1.0 - Multiple Vulnerabilities
by Claudio Viviani
EIP-2026-100469 EXPLOITDB python
Onlineon E-Ticaret - Database Disclosure
by ZoRLu
EIP-2026-116225 EXPLOITDB python
Seafile-server 3.1.5 - Remote Denial of Service
by nop nop
CVE-2014-5460 EXPLOITDB python VERIFIED
Tribulant Slideshow Gallery < 1.4.7 - Authenticated Arbitrary File Upload
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
by Claudio Viviani
EIP-2026-105068 EXPLOITDB python
ALCASAR 2.8.1 - Remote Code Execution
by eF
EIP-2026-108868 EXPLOITDB python
Joomla! Component Spider Contacts 1.3.6 - 'contacts_id' SQL Injection
by Claudio Viviani
EIP-2026-103058 EXPLOITDB python
ALCASAR 2.8 - Remote Code Execution
by eF
EIP-2026-108864 EXPLOITDB python
Joomla! Component Spider Calendar 3.2.6 - SQL Injection
by Claudio Viviani
EIP-2026-117410 EXPLOITDB python VERIFIED
LeapFTP 3.1.0 - URL Handling Buffer Overflow (SEH)
by k3170makan
EIP-2026-117288 EXPLOITDB python VERIFIED
HTML Help Workshop 1.4 - Local Buffer Overflow (SEH)
by mr.pr0n
EIP-2026-115399 EXPLOITDB python VERIFIED
HTML Help Workshop 1.4 - Buffer Overflow (SEH) (PoC)
by Moroccan Kingdom (MKD)
CVE-2014-2913 EXPLOITDB python
Nagios Remote Plugin Executor <2.15 - RCE
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments
by Claudio Viviani
CVE-2014-5520 EXPLOITDB python
xrms_crm - SQL Injection via user_id Parameter
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php.
by Benjamin Harris
CVE-2014-5521 EXPLOITDB python
xrms_crm - Authenticated Remote Code Execution via Username Parameter
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.
by Benjamin Harris
CVE-2014-2223 EXPLOITDB python
Plogger < 1.0 - Authenticated Arbitrary File Upload and Remote Code Execution via ZIP Archive
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/.
by b0z
CVE-2014-5519 EXPLOITDB python
PhpWiki 1.5.0 - Remote Code Execution via Ploticus Module Device Option
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.
by Benjamin Harris