Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-107050 EXPLOITDB text VERIFIED
Farsinews 2.5.3 - Multiple Cross-Site Scripting Vulnerabilities
by O.U.T.L.A.W.
CVE-2006-2070 EXPLOITDB text VERIFIED
DevBB 1.0.0 - Cross-Site Scripting via Member Parameter
Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action.
by Qex
EIP-2026-106302 EXPLOITDB text VERIFIED
CuteNews 1.4.1 - Multiple Cross-Site Scripting Vulnerabilities
by outlaw.dll
CVE-2006-2505 EXPLOITDB text VERIFIED
Oracle Database Server 10g Release 2 - SQL Injection
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious package in the TYPE_NAME argument in the (1) GET_DOMAIN_INDEX_TABLES or (2) GET_V2_DOMAIN_INDEX_TABLES function in the DBMS_EXPORT_EXTENSION package.
by N1V1Hd
CVE-2006-2048 EXPLOITDB text VERIFIED
phpWebFTP 2.3 - Cross-Site Scripting via Port, Server, or User Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) port, (2) server, and (3) user parameters. NOTE: it is possible that the affected version is actually 3.2.
by arko.dhar
CVE-2006-2040 EXPLOITDB text VERIFIED
photokorn 1.53 and 1.542 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.
by Dr.Jr7
CVE-2006-2040 EXPLOITDB text VERIFIED
photokorn 1.53 and 1.542 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.
by Dr.Jr7
CVE-2006-2040 EXPLOITDB text VERIFIED
photokorn 1.53 and 1.542 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.
by Dr.Jr7
CVE-2006-2051 EXPLOITDB text VERIFIED
NextAge Shopping Cart - Stored Cross-Site Scripting via Username and Password Parameters
Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.
by R@1D3N
CVE-2006-2052 EXPLOITDB text VERIFIED
Verosky Media Instant Photo Gallery - Cross-Site Scripting via Member Parameter
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.
by Qex
CVE-2006-2079 EXPLOITDB text VERIFIED
Verosky Media Instant Photo Gallery - Cross-Site Scripting via portfolio.php cat_id Parameter
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
by Qex
CVE-2006-2052 EXPLOITDB text VERIFIED
Verosky Media Instant Photo Gallery - Cross-Site Scripting via Member Parameter
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.
by Qex
CVE-2007-2290 EXPLOITDB text VERIFIED
B2 Weblog and News Publishing Tool 0.6.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.
by alijsb
CVE-2007-2290 EXPLOITDB text VERIFIED
B2 Weblog and News Publishing Tool 0.6.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.
by alijsb
CVE-2007-2290 EXPLOITDB text VERIFIED
B2 Weblog and News Publishing Tool 0.6.1 - RCE
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466.
by alijsb
CVE-2006-2046 EXPLOITDB text VERIFIED
Cartweaver ColdFusion < 2.16.11 - SQL Injection via Category, Keywords, or ProdID Parameter
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.
by r0t
CVE-2006-2001 EXPLOITDB text VERIFIED
Scry Gallery 1.1 - Cross-Site Scripting via p Parameter
Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector.
by mayank
CVE-2005-3302 EXPLOITDB HIGH text VERIFIED
Blender - Remote Code Execution via Malicious BVH File Hierarchy Element
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
by Joxean Koret
CVSS 7.3
CVE-2005-1287 EXPLOITDB text VERIFIED
BK Forum < 4 - SQL Injection via Member ID or Forum Parameter
Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.
by n0m3rcy
CVE-2006-2012 EXPLOITDB text VERIFIED
Skulltag < 0.96f - Denial of Service via Version String Format String Vulnerability
Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.
by Luigi Auriemma
CVE-2006-2005 EXPLOITDB text VERIFIED
ClanSys 1.1 - Remote Code Execution via Page Parameter Eval Injection
Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.
by nukedx
CVE-2006-2008 EXPLOITDB text VERIFIED
Built2Go PHP Movie Review <2B - RCE
PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.
by Camille Myers
CVE-2006-1999 EXPLOITDB text VERIFIED
OpenTTD 0.4.7 - Denial of Service via Malformed UDP Packet
The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.
by Luigi Auriemma
CVE-2006-1992 EXPLOITDB text VERIFIED
Internet Explorer - Denial of Service via Nested OBJECT Tags
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
by Michal Zalewski
CVE-2006-2028 EXPLOITDB text VERIFIED
simplog < 0.9.3 - Cross-Site Scripting via imagedir Parameter
Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. NOTE: this issue might be resultant from directory traversal.
by nukedx