Exploitdb Exploits
31,394 exploits tracked across all sources.
Caucho Resin <3.0.18 - Info Disclosure
The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.
by Joseph Pierini
GNUnet < 0.7.0d - Denial of Service via Empty UDP Datagram
GNUnet before SVN revision 2781 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an empty UDP datagram, possibly involving FIONREAD errors.
by Luigi Auriemma
Florian Amrhein NewsPortal < 0.37 - Remote File Inclusion via file_newsportal Parameter
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
by Kacper
Squirrelcart <= 2.2.2 - Remote File Inclusion via cart_isp_root Parameter
PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.
by OLiBekaS
PopSoft Digital PopPhoto Studio <= 3.5.4 - Remote Code Execution via include_path Parameter
PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has notified CVE that "PopPhoto is NOT a product of Pixaria. It was a product of PopSoft Digital and is only hosted by Pixaria as a courtesy... The vulnerability listed was patched by the previous vendor and all previous users have received this update."
by VietMafia
phpodp 1.5h - Cross-Site Scripting via Browse Parameter
Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter.
by Kiki
PSY Auction - SQL Injection via item.php id Parameter
SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Luny
PSY Auction - Cross-Site Scripting via email_request.php user_id Parameter
Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Luny
ezusermanager 1.6 - Remote File Inclusion via ezUserManager_Path Parameter
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php.
by OLiBekaS
Confixx 3.1.2 - Cross-Site Scripting via ftplogin/index.php login parameter
Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter.
by LoK-Crew
Raydium - Denial of Service via Large ID in raydium_network_read
The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a large ID, which causes an invalid memory access (buffer over-read).
by Luigi Auriemma
Outgun <= 1.0.3 bot 2 - Buffer Overflow via Long Registration String
Buffer overflow in the changeRegistration function in servernet.cpp for Outgun 1.0.3 bot 2 and earlier allows remote attackers to change the registration information of other players via a long string.
by Luigi Auriemma
Genecys < 0.2 - Denial of Service via Missing Colon in Command
The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (colon) separator, which triggers a null dereference.
by Luigi Auriemma
Empire 4.3.2 - Denial of Service via Long Text Strings in Client Buffer
The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.
by Luigi Auriemma
GPhotos < 1.5 - Directory Traversal via Rep Parameter
Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rep parameter.
by Morocco Security Team
GPhotos <= 1.5 - Cross-Site Scripting via rep or image Parameter
Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal.
by Morocco Security Team
GPhotos <= 1.5 - Cross-Site Scripting via rep or image Parameter
Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal.
by Morocco Security Team
GPhotos <= 1.5 - Cross-Site Scripting via rep or image Parameter
Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal.
by Morocco Security Team
PHPBB 2.0.20 - Server-Side Request Forgery via Avatar URL Parameter
usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.
by rgod
PHP Blue Dragon Platinum 2.8.0 - RCE
PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.
by Kacper
ozjournals 1.2 - Cross-Site Scripting via vname Parameter
Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality.
by Kiki
Teake Nutma Foing 0.2.0-0.7.0 - RCE
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) index.php, (2) song.php, (3) faq.php, (4) list.php, (5) gen_m3u.php, and (6) playlist.php.
by Kurdish Security
IPswitch WhatsUp Professional 2006 - Cross-Site Scripting via sDeviceView, nDeviceID, or sHostname Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.
by David Maciejak
IPswitch WhatsUp Professional 2006 - Cross-Site Scripting via sDeviceView, nDeviceID, or sHostname Parameter
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.
by David Maciejak
vizra - Cross-Site Scripting via message Parameter in a_login.php
Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.
by R00TT3R
By Source