Exploitdb Exploits
31,394 exploits tracked across all sources.
Mybulletinboard - SQL Injection
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.
by Devil-00
FarsiNews < 2.1_beta2 - Remote File Inclusion via loginout.php cutepath Parameter
PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter.
by Hamid Ebadi
Cerberus Helpdesk - Cross-Site Scripting via Contact Search Parameter
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
by preben@watchcom.no
spaiz-nuke_cms - Cross-Site Scripting via Articles Module Query Parameter
Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the query parameter in the search file.
by night_warrior771
PmWiki 2.1 beta 20 - Remote File Inclusion and Cross-Site Scripting via Global Variable Bypass
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).
by aScii
ashNews 0.83 - Cross-Site Scripting via id Parameter
Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
by 0o_zeus_o0
Mozilla Firefox - Cross-Site Scripting via -moz-binding CSS Property
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.
by Chris Thomas
Daffodil CRM 1.5 - SQL Injection via userlogin.jsp
SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.
by preben@watchcom.no
UBB.threads 6.3 - SQL Injection via showflat.php Number Parameter
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.
by k-otik
phpBB 2.0.19 - Cross-Site Scripting Remote Cookie Disclosure
by threesixthousan
GNOME Evolution - Denial of Service via Long Line in Inline Text Attachment
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.
by Mike Davis
Oracle HTTP Server <10.1.0.5-10.1.2.0.2 - Unspecified
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.
by Argeniss
my little homepage my little weblog - Cross-Site Scripting via BBcode Link Tag
Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.
by Aliaksandr Hartsuyeu
AndoNET Blog 2004.09.02 - SQL Injection via Entrada Parameter
SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.
by Aliaksandr Hartsuyeu
Exiv2 < 0.9 - Denial of Service via IPTC Metadata Buffer Overflow
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.
by Maciek Wierciski
Elido Face Control - Multiple Directory Traversal Vulnerabilities
by HSC Security Group
ExpressionEngine 1.4.1 - Cross-Site Scripting via HTTP_REFERER Header
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).
by Aliaksandr Hartsuyeu
CheesyBlog 1.0 - Stored Cross-Site Scripting via Archive Comment Parameters
Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment.
by Aliaksandr Hartsuyeu
SleeperChat < 0.3f - Cross-Site Scripting via Pseudo Parameter
Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.
by hackologie
Pixelpost Photoblog 1.4.3 - Stored Cross-Site Scripting via Add Comment Field
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.
by Aliaksandr Hartsuyeu
MyBB 1.02 - Cross-Site Scripting via usercp.php Notepad and Signature Parameters
Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.
by Roozbeh Afrasiabi
miniBloggie < 1.0 - SQL Injection via Login Parameters
SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.
by Aliaksandr Hartsuyeu
123 Flash Chat Server <5.1 - Code Injection
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.
by Jesus Olmos Gonzalez
NewsPHP - SQL Injection via discuss, tim, id, last, or limit Parameter
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.
by SAUDI
e-moBLOG 1.3 - Multiple SQL Injections
by Aliaksandr Hartsuyeu
By Source