Exploitdb Exploits
31,394 exploits tracked across all sources.
inTouch 0.5.1 Alpha - SQL Injection via User Parameter
SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.
by Aliaksandr Hartsuyeu
Chimera Web Portal System 0.2 - Cross-Site Scripting via Guestbook Module Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.
by Aliaksandr Hartsuyeu
Phanatic Softwares Chimera Web Portal System 0.2 - SQL Injection via linkcategory.php id Parameter
SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Aliaksandr Hartsuyeu
IBM AIX 5.3 ML03 - Local Directory Traversal via getCommand and getShell
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.
by xfocus
phpDocumentor 1.2/1.3 - Forum Lib Variable Cross-Site Scripting
by zeus olimpusklan
OoApp Guestbook 2.1 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by r0t3d3Vil
Kayako SupportSuite <= 3.00.26 - Cross-Site Scripting via Multiple Input Fields
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) nav parameter in the downloads module, (2) Full Name and (3) Email fields in the core module, (4) Full Name, (5) Email, and (6) Subject fields in the tickets module, or (7) Registered Email field in the lostpassword feature in the core module.
by r0t3d3Vil
AdesGuestbook 2.0 - Cross-Site Scripting via totalRows_rsRead Parameter
Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter.
by r0t3d3Vil
WebWiz Products 1.0/3.06 - Authentication Bypass / SQL Injection
by DevilBox
IBM AIX 5.3 ML03 - Local Directory Traversal via getCommand and getShell
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.
by xfocus
VEGO Links Builder 2.0 Login Script - SQL Injection
by Aliaksandr Hartsuyeu
GNU phpBook <= 1.3.2 - Remote Code Execution via Email Field
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
by Aliaksandr Hartsuyeu
oaBoard 1.0 - Remote Code Execution
PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.
by Aliaksandr Hartsuyeu
PHPenpals < 1.1 - SQL Injection via profile.php personalID Parameter
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.
by Aliaksandr Hartsuyeu
GmailSite/GFHost <1.0.4/<0.4.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.
by Lostmon
Chipmunk Guestbook 1.4 - Homepage HTML Injection
by Aliaksandr Hartsuyeu
VEGO Web Forum 1.x - Theme_ID SQL Injection
by Aliaksandr Hartsuyeu
phpclanwebsite - Cross-Site Scripting via BBCode img Tag
Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.
by kurdish hackers team
Koobi 5 - Cross-Site Scripting via Nested Malformed URL BBCode Tags
Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via nested, malformed url BBCode tags. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by kurdish hackers team
Microsoft Internet Explorer 5.0.1 - HTML Parsing Denial of Service
by Christian Deneke
IceWarp Web Mail <5.5.1 - Code Injection
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.
by Tan Chew Keong
IceWarp Web Mail <5.5.1 - Code Injection
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.
by Tan Chew Keong
IceWarp Web Mail 5.5.1 - Info Disclosure
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files via a request with an unrecognized User Agent that also specifies the desired default_layout and layout_settings parameters.
by Tan Chew Keong
By Source