Exploitdb Exploits
31,394 exploits tracked across all sources.
Apache Geronimo 1.0 - Cross-Site Scripting via cal2.jsp Time Parameter and Invalid Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
by Oliver Karow
Apache Geronimo 1.0 - Cross-Site Scripting via cal2.jsp Time Parameter and Invalid Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
by Oliver Karow
AmbiCom Blue Neighbors 2.50 build 2500 - BlueTooth Stack Object Push Buffer Overflow
by Kevin Finisterre
Ultimate Auction 3.67 - Cross-Site Scripting via Item and Category Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.
by querkopf
faq-o-matic < 2.711 - Cross-Site Scripting via _duration, file, or cmd Parameters
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.
by Preddy
Simple Blog < 2.1 - SQL Injection via Month Parameter
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.
by Zinho
EZDatabaseRemote 2.0 - PHP Script Code Execution
by r0t3d3Vil
Ultimate Auction 3.67 - Cross-Site Scripting via Item and Category Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.
by querkopf
Mini-Nuke CMS System < 1.8.2 - SQL Injection via news.asp hid Parameter
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
by nukedx
DCP Portal 5.3/6.0/6.1 - Multiple Input Validation Vulnerabilities
by night_warrior771
AlstraSoft Template Seller Pro - Cross-Site Scripting via fullview.php tempid Parameter
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.
by night_warrior771
Helm Hosting Control Panel <= 3.2.8 - Cross-Site Scripting via forgotPassword.asp txtEmailAddress Parameter
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.
by M.Neset KABAKLI
Microsoft Visual Studio .NET - Remote Code Execution via Malicious Project File
By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
by priestmaster
TankLogger 2.4 - SQL Injection via livestock_id or tank_id Parameter
SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.
by Aliaksandr Hartsuyeu
Interspire TrackPoint NX < 0.1 - Cross-Site Scripting via Login Username Parameter
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.
by M.Neset KABAKLI
FogBugz < 4.0.33 - Cross-Site Scripting via dest Parameter
Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.
by M.Neset KABAKLI
Apple QuickTime < 7.0.4 - Remote Code Execution via Crafted Image File
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.
by Dennis Rand
MyPhPim 01.05 - SQL Injection via cal_id Parameter or Login Password Field
SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.
by Aliaksandr Hartsuyeu
MyPhPim 01.05 - SQL Injection via cal_id Parameter or Login Password Field
SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.
by Aliaksandr Hartsuyeu
OrjinWeb E-commerce - Remote File Inclusion via Page Parameter
PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.
by serxwebun
Cray UNICOS 9.0.2.2 - Local Privilege Escalation via Long Command Line Argument or File Line
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.
by Micheal Turner
Cray UNICOS 9.0.2.2 - Local Privilege Escalation via Long Command Line Argument or File Line
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.
by Micheal Turner
Hummingbird Collaboration <5.21 - XSS
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.
by Luca Carettoni
Hummingbird Collaboration <5.21 - Info Disclosure
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.
by Luca Carettoni
Web Wiz Forums 6.34 - Cross-Site Scripting via Search Parameter
Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
by nukedx
By Source