Exploitdb Exploits
31,394 exploits tracked across all sources.
AZ Bulletin Board <= 1.1.00 - Cross-Site Scripting via Nickname Parameter or Topic Parameter
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.
by Roozbeh Afrasiabi
Insane Visions BlogPHP - SQL Injection via Cookie Parameters
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.
by imei
Rockliffe MailSite < 6.1.22 - Cross-Site Scripting via WCONSOLE.DLL Query String
Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.
by OS2A BTO
WebspotBlogging 3.0 - SQL Injection via Login Username Parameter
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.
by Aliaksandr Hartsuyeu
ASPThai Forums 8.0 - 'login.asp' SQL Injection
by code.shell
SaralBlog 1.0 - SQL Injection via Search Parameter
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.
by Aliaksandr Hartsuyeu
eggblog 2.0 - Cross-Site Scripting via Topic Message Field
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.
by alex@evuln.com
eggblog 2.0 - SQL Injection via blog.php id Parameter
SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.
by alex@evuln.com
CA BrightStor Mobile Backup and ARCserve Backup - Denial of Service via Large Network Packet
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.
by Karma
PowerPortal - SQL Injection via Search Parameter
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
by night_warrior771
PowerPortal - SQL Injection via Search Parameter
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
by night_warrior771
microBlog 2.0 RC-10 - SQL Injection via Month or Year Parameter
SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.
by Aliaksandr Hartsuyeu
aoblogger 2.3 - Stored Cross-Site Scripting via BBcode URL Tag
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.
by Aliaksandr Hartsuyeu
aoblogger 2.3 - SQL Injection via Username Parameter
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.
by Aliaksandr Hartsuyeu
aoblogger 2.3 - Unauthenticated Blog Entry Creation via uza Parameter
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.
by Aliaksandr Hartsuyeu
Microsoft Internet Explorer 5.0.1 - Malformed .IMG / .XML Parsing Denial of Service
by Inge Henriksen
WhiteAlbum 2.5 - SQL Injection via Pictures.php Dir Parameter
SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.
by liz0
RedKernel Referrer Tracker 1.1.0-3 - Stored Cross-Site Scripting via Query String
Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
by Preddy
phpXplorer 0.9.33 - Directory Traversal via sShare Parameter
Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root
by Oriol Torrent Santiago
PHPXplorer 0.9.33 - 'action.php' Directory Traversal
by liz0
GTP iCommerce - Cross-Site Scripting via cat and subcat Parameters
Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Preddy
EZDatabase < 2.1.1 - Directory Traversal and Cross-Site Scripting via p Parameter
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.
by Josh Zlatin-Amishav
BlogPHP 1.0 - SQL Injection via Username Parameter
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.
by Aliaksandr Hartsuyeu
bit_5_blog < 8.01 - SQL Injection via Username or Password Parameter
SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.
by Aliaksandr Hartsuyeu
bit_5_blog 8.01 - Stored Cross-Site Scripting via Comment Parameter
Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.
by Aliaksandr Hartsuyeu
By Source