Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-1413 EXPLOITDB text VERIFIED
EZHomepagePro < 1.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.
by r0t
CVE-2006-1413 EXPLOITDB text VERIFIED
EZHomepagePro < 1.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.
by r0t
CVE-2006-1413 EXPLOITDB text VERIFIED
EZHomepagePro < 1.5 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.
by r0t
CVE-2006-1418 EXPLOITDB text VERIFIED
Caloris Planitia E-School Mgt Sys <1.0 - XSS
Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
by r0t
CVE-2006-1422 EXPLOITDB text VERIFIED
PHP Booking Calendar <1.0c - SQL Injection
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
by undefined1_
CVE-2006-1497 EXPLOITDB text VERIFIED
ViHor Design - Directory Traversal via Page Parameter
Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.
by botan
CVE-2006-1496 EXPLOITDB text VERIFIED
ViHor Design - Cross-Site Scripting via Page Parameter
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.
by botan
CVE-2006-1395 EXPLOITDB text VERIFIED
Cholod MySQL Based Message Board - SQL Injection
SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
by kspecial
CVE-2006-1377 EXPLOITDB text VERIFIED
EasyMoblog <0.5.1 & CoMoblog 1.1 - XSS
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
by FarhadKey
CVE-2006-1377 EXPLOITDB text VERIFIED
EasyMoblog <0.5.1 & CoMoblog 1.1 - XSS
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
by FarhadKey
CVE-2006-1384 EXPLOITDB text VERIFIED
IBM Tivoli Business Systems Manager <3.1.0.1 - XSS
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.
by anonymous
CVE-2006-1367 EXPLOITDB text VERIFIED
Motorola PEBL U6 08.83.76R - Info Disclosure
The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and view phonebook entries and saved SMS messages by connecting on Bluetooth channel 3 and tricking the user into pressing Grant, aka a "Blueline" attack. NOTE: while user-assisted, the attack is made more feasible because of a GUI misrepresentation issue that allows a default message to be replaced by an attacker-specified one.
by kspecial
CVE-2006-1372 EXPLOITDB text VERIFIED
1WebCalendar < 4.0 - SQL Injection via EventID, NewsID, or ThisDate Parameter
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
by r0t3d3Vil
CVE-2006-1372 EXPLOITDB text VERIFIED
1WebCalendar < 4.0 - SQL Injection via EventID, NewsID, or ThisDate Parameter
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
by r0t3d3Vil
CVE-2006-1372 EXPLOITDB text VERIFIED
1WebCalendar < 4.0 - SQL Injection via EventID, NewsID, or ThisDate Parameter
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.
by r0t3d3Vil
CVE-2006-1356 EXPLOITDB text VERIFIED
LibVC 3 - Stack-Based Buffer Overflow via Long Line in vCard File
Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a vCard file (e.g. contacts.vcf) containing a long line.
by trew
CVE-2006-1357 EXPLOITDB text VERIFIED
F5 Firepass 4100 SSL VPN 5.4.2 - XSS
Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by ILION Research
CVE-2006-1330 EXPLOITDB text VERIFIED
phpwebsite <= 0.83 - SQL Injection via sid Parameter
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
by DaBDouB-MoSiKaR
CVE-2006-1330 EXPLOITDB text VERIFIED
phpwebsite <= 0.83 - SQL Injection via sid Parameter
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
by DaBDouB-MoSiKaR
CVE-2006-0745 EXPLOITDB text VERIFIED
X.Org server <1.0.0 - Privilege Escalation
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
by H D Moore
CVE-2006-1344 EXPLOITDB text VERIFIED
VeriSign MPKI 6.0 - Cross-Site Scripting via VHTML_FILE Parameter
Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the VHTML_FILE parameter.
by Alberto Soli
CVE-2006-1324 EXPLOITDB text VERIFIED
Woltlab Burning Board < 1.0.2pl2e_lite - Cross-Site Scripting via errormsg Parameter
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
by r57shell
CVE-2005-4500 EXPLOITDB text VERIFIED
MusicBox 2.3 - SQL Injection via Show or Type Parameter
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.
by Linux_Drox
CVE-2006-1349 EXPLOITDB text VERIFIED
Musicbox 2.3 Beta 2 - Cross-Site Scripting via id, type, show, and message1 Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.
by Linux_Drox
CVE-2006-1349 EXPLOITDB text VERIFIED
Musicbox 2.3 Beta 2 - Cross-Site Scripting via id, type, show, and message1 Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.
by Linux_Drox