Exploitdb Exploits
31,394 exploits tracked across all sources.
CyberOffice Warehouse Builder - Cross-Site Scripting via SessionID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2 might be resultant from SQL injection.
by r0t
Smartwin Technology Cyberoffice Warehouse Builder - SQL Injection
Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.
by r0t
CyberOffice Warehouse Builder - Cross-Site Scripting via SessionID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2 might be resultant from SQL injection.
by r0t
Smartwin Technology Cyberoffice Warehouse Builder - SQL Injection
Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.
by r0t
CyberOffice Warehouse Builder - Cross-Site Scripting via SessionID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2 might be resultant from SQL injection.
by r0t
zenphoto < 1.0.1_beta - Cross-Site Scripting via i.php a Parameter and index.php album/image Parameters
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.
by zone14
zenphoto < 1.0.1_beta - Cross-Site Scripting via i.php a Parameter and index.php album/image Parameters
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.
by zone14
Virtual Hosting Control System - Cross-Site Scripting via day/month/year Parameters
Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter.
by O.U.T.L.A.W
Pinnacle Cart <= 3.33 - Cross-Site Scripting via setbackurl Parameter
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.
by r0t
JSBoard < 2.0.12 - Cross-Site Scripting via parse_query_str Function
Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are set as global variables within the program, as demonstrated using the table parameter to login.php.
by Alexander Klink
geoblog 1.0 - Cross-Site Scripting via viewcat.php cat Parameter
Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
by SubjectZero
albinator < 2.0.8 - Cross-Site Scripting via cid or preloadSlideShow Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php.
by r0t
albinator < 2.0.8 - Cross-Site Scripting via cid or preloadSlideShow Parameter
Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php.
by r0t
SunShop Shopping Cart <= 3.5 - Cross-Site Scripting via Multiple Index.php Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php.
by r0t
phpBB Knowledge Base 2.0.2 - 'Mod KB_constants.php' Remote File Inclusion
by [Oo]
OrbitHYIP 2.0 - Cross-Site Scripting via Referral or ID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
by r0t
OrbitHYIP 2.0 - Cross-Site Scripting via Referral or ID Parameter
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
by r0t
MaxTrade 1.0.1 - SQL Injection via pocategories.php Parameters
SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categori and (2) stranica parameters.
by r0t
DMCounter 0.9.2-b - Remote File Inclusion via kopf.php rootdir Parameter
PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.
by beford
Collaborative Portal Server <= 3.4.0 - Cross-Site Scripting via popup_image pos Argument
Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.
by r0t
macOS 10.4 - Denial of Service via Crafted OpenEXR Image File
Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.
by Christian
xine 0.99.4 - Denial of Service via Format String in MP3 Filename
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.
by KaDaL-X
Hogstorps hogstorp Guestbook 2.0 - Info Disclosure
admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.
by omnipresent
phpMyAgenda 3.0 Final - 'rootagenda' Remote File Inclusion
by Aesthetico
By Source