Exploitdb Exploits
31,394 exploits tracked across all sources.
Dia 0.94 - Format String Vulnerability via Crafted .bmp Filename
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.
by KaDaL-X
UBB.threads <6.5.2,6.5.1.1(trial) - RCE
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.
by V4mu
perlpodder < 0.5 - Remote Code Execution via Podcast URL Shell Metacharacters
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
by RedTeam Pentesting
CaLogic Calendars 1.2.2 - Remote File Inclusion via GLOBALS[CLPath] Parameter
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue.
by Kacper
phpMyDirectory <= 10.4.4 - Remote Code Execution via ROOT_PATH Parameter
PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.
by OLiBekaS
phpBazar 2.1.0 - Remote File Inclusion via Language_dir Parameter
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.
by [Oo]
Jemscripts DownloadControl 1.0 - Information Disclosure via Invalid dcid Parameter
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in functions.php.
by Luny
artmedic newsletter 4.1 - Arbitrary File Write and Remote Code Execution via logfile Parameter
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as demonstrated by injecting PHP code into info.php.
by C.Schmitz
Zixforum 1.12 - SQL Injection via layid Parameter
SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands via the layid parameter to (1) login.asp and (2) main.asp.
by FarhadKey
CodeAvalanche News 1.2 - SQL Injection via Password Field
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
by omnipresent
cosmoshop < 8.11.106 - SQL Injection via artnum Parameter
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.
by l0om
AspBB 0.5.2 - Cross-Site Scripting via Action or Get Parameter
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to default.asp or (2) get parameter to profile.asp.
by TeufeL
AspBB 0.5.2 - Cross-Site Scripting via Action or Get Parameter
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to default.asp or (2) get parameter to profile.asp.
by TeufeL
ScozNews < 1.2.1 - Remote File Inclusion via CONFIG[main_path] Parameter
Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[main_path] parameter in (1) functions.php, (2) template.php, (3) news.php, (4) help.php, (5) mail.php, (6) Admin/admin_cats.php, (8) Admin/admin_edit.php, (9) Admin/admin_import.php, and (10) Admin/admin_templates.php. NOTE: this might be resultant from a variable overwrite issue.
by Kacper
Quezza BB < 1.0 - Remote File Inclusion via quezza_root_path Parameter
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter.
by nukedx
BoastMachine < 3.1 - Cross-Site Scripting via PHP_SELF Query String
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.
by Yunus Emre Yilmaz
RealVNC 4.1.0 < 4.1.1 - VNC Null Authentication Scanner
by class101
libextractor <= 0.5.13 - Remote Code Execution via ASF and QT Plugin Buffer Overflow
Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).
by Luigi Auriemma
Mobotix IP Network Camera <2.2.3.18 (M10/D10) & <3.0.3.31 (M22) XSS via URL-Encoded Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.
by Jaime Blasco
Mobotix IP Network Camera <2.2.3.18 (M10/D10) & <3.0.3.31 (M22) XSS via URL-Encoded Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.
by Jaime Blasco
Mobotix IP Network Camera <2.2.3.18 (M10/D10) & <3.0.3.31 (M22) XSS via URL-Encoded Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.
by Jaime Blasco
Ipswitch WhatsUp Professional 2006 - Auth Bypass
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
by Kenneth F. Belva
OpenWiki 0.78 - Cross-Site Scripting via p Parameter
Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites.
by LiNuX_rOOt
Sphider 1.3 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
by Soot
phpremoteview < 2003-10-23 - Cross-Site Scripting via f, d, ref Parameters and MAKE DIR, Full file name Fields
Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields.
by Soot
By Source