Exploitdb Exploits
31,394 exploits tracked across all sources.
phpBB Chart mod - SQL Injection via id Parameter
SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.
by sn4k3.23
phpBB Chart mod - Cross-Site Scripting via id Parameter
Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
by sn4k3.23
Geeklog <= 1.4.0sr2 - Cross-Site Scripting via getimage.php Image Parameter
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.
by trueend5
GNU Binutils < 2.17 - Buffer Overflow in TekHex Record Handling
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
by Jesus Olmos Gonzalez
CVSS 7.3
Microsoft Infotech Storage System Library - Heap-based Buffer Overflow via Crafted CHM/ITS File
Heap-based buffer overflow in Microsoft Infotech Storage System Library (itss.dll) allows user-assisted attackers to execute arbitrary code via a crafted CHM / ITS file that triggers the overflow while decompiling.
by Ruben Santamarta
phpRaid 3.0.b3 - 'phpBB'/'SMF' Remote File Inclusion
by Kurdish Security
mxbb_portal - Remote File Inclusion via module_root_path Parameter
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
by Darkfire
MyBulletinBoard 1.1.1 - SQL Injection via showthread.php Comma Parameter
SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.
by Breeeeh
EImagePro - SQL Injection via CatID, SubjectID, or Pic Parameter
Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.
by Dj_Eyes
MultiCalendars 3.0 - SQL Injection via calsids Parameter
SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Dj_Eyes
EPublisherPro - Cross-Site Scripting via Title Parameter
Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Dj_Eyes
EImagePro - SQL Injection via CatID, SubjectID, or Pic Parameter
Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.
by Dj_Eyes
EDirectoryPro < 2.0 - SQL Injection via search_result.asp Keyword Parameter
SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by Dj_Eyes
Dynamic Galerie 1.0 - Cross-Site Scripting via pfad Parameter
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal.
by d4igoro
Dynamic Galerie 1.0 - Path Traversal via pfad Parameter
Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.
by d4igoro
Dynamic Galerie 1.0 - Path Traversal via pfad Parameter
Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.
by d4igoro
Dynamic Galerie 1.0 - Cross-Site Scripting via pfad Parameter
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal.
by d4igoro
singapore 0.9.7 - Cross-Site Scripting via Image Parameter
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
by alp_eren@ayyildiz.org
phpListPro < 2.01 - Remote File Inclusion via returnpath Parameter
Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749.
by Aesthetico
Phil's Bookmark Script - 'admin.php' Authentication Bypass
by alp_eren@ayyildiz.org
openEngine <= 1.8 Beta 2 - Directory Traversal via Template Parameter
Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template parameter.
by ck@caroli.info
evoTopsites 2.x and evoTopsites Pro 2.x - SQL Injection via cat_id or id Parameter
SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.
by Hamid Ebadi
Creative Community Portal <= 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
by r0t
Creative Community Portal <= 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
by r0t
Creative Community Portal <= 1.1 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
by r0t
By Source