Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-4557 EXPLOITDB text VERIFIED
IceWarp Web Mail <5.5.1 - Path Traversal
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability.
by Tan Chew Keong
CVE-2005-4556 EXPLOITDB text VERIFIED
VisNetic Mail Server 8.3.0 build 1 - Remote File Inclusion via lang_settings or language Parameter
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.
by Tan Chew Keong
CVE-2005-4556 EXPLOITDB text VERIFIED
VisNetic Mail Server 8.3.0 build 1 - Remote File Inclusion via lang_settings or language Parameter
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.
by Tan Chew Keong
CVE-2005-4554 EXPLOITDB text VERIFIED
DEV web management system <1.5 - SQL Injection
Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php.
by retrogod@aliceposta.it
CVE-2005-4554 EXPLOITDB text VERIFIED
DEV web management system <1.5 - SQL Injection
Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in an openforum action (openforum.php) in index.php, (2) cat parameter in getfile.php, and (3) target parameter in download_now.php.
by retrogod@aliceposta.it
CVE-2005-4555 EXPLOITDB text VERIFIED
DEV web management system <1.5 - XSS
Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ENTER_ARTICLE_TITLE, (2) SPECIFY_ZONE, (3) ENTER_ARTICLE_HEADER, and (4) ENTER_ARTICLE_BODY indices in the language array parameter.
by retrogod@aliceposta.it
CVE-2005-4427 EXPLOITDB text VERIFIED
Cerberus Helpdesk - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.
by A. Ramos
CVE-2005-4427 EXPLOITDB text VERIFIED
Cerberus Helpdesk - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.
by A. Ramos
CVE-2005-4427 EXPLOITDB text VERIFIED
Cerberus Helpdesk - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.
by A. Ramos
CVE-2005-4576 EXPLOITDB text VERIFIED
Fatwire UpdateEngine < 6.2 - Cross-Site Scripting via COUNTRYNAME, EMAIL, or FUELAP_TEMPLATENAME Parameters
Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.
by r0t3d3Vil
CVE-2006-0470 EXPLOITDB text VERIFIED
MyBulletinBoard 1.02 - Cross-Site Scripting via search.php sortby and sortordr Parameters
Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.
by imei
EIP-2026-108051 EXPLOITDB text VERIFIED
Jax Calendar 1.34 - 'jax_calendar.php' SQL Injection
by r0t3d3Vil
CVE-2005-4430 EXPLOITDB text VERIFIED
LogicBill <= 1.0 - SQL Injection via helpdesk.php __mode and __id Parameters
SQL injection vulnerability in LogicBill 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) __mode and (2) __id parameters to helpdesk.php.
by r0t3d3Vil
CVE-2005-3845 EXPLOITDB text VERIFIED
EZ Invoice Inc 2.0 - SQL Injection via invoices.php i Parameter
SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email support@ezinvoiceinc.com and EZI will email you the patch to fix this small issue."
by r0t3d3Vil
EIP-2026-106963 EXPLOITDB text VERIFIED
Exponent CMS 0.95 - Multiple Cross-Site Scripting Vulnerabilities
by y3dips
CVE-2005-4429 EXPLOITDB text VERIFIED
CS-Cart 1.3.0 - SQL Injection via sort_by or sort_order Parameters
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
by r0t3d3Vil
CVE-2005-4550 EXPLOITDB text VERIFIED
Oracle Application Server Discussion Forum Portlet - Unauthenticated Arbitrary File Read via df_next_page Parameter
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).
by Johannes Greil
CVE-2005-4574 EXPLOITDB text VERIFIED
CommonSpot Content Server <= 4.5 - Cross-Site Scripting via loader.cfm bNewWindow Parameter
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.
by r0t3d3Vil
CVE-2005-4500 EXPLOITDB text VERIFIED
MusicBox 2.3 - SQL Injection via Show or Type Parameter
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.
by Medo HaCKer
CVE-2005-4461 EXPLOITDB text VERIFIED
Beehive Forum <0.6.2 - SQL Injection
SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter.
by trueend5
CVE-2005-4504 EXPLOITDB text VERIFIED
Safari and TextEdit - Denial of Service via Large ROWSPAN Attribute in TD Tag
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
by Tom Ferris
CVE-2005-4502 EXPLOITDB text VERIFIED
httprint v202 - Cross-Site Scripting via Server Field in HTTP Response
Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user.
by Mariano Nunez Di Croce
CVE-2005-4503 EXPLOITDB text VERIFIED
httprint v202 - Denial of Service via Long Server Field in HTTP Response
httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response.
by Mariano Nunez Di Croce
CVE-2005-4497 EXPLOITDB text VERIFIED
Tangora Portal CMS < 4.0 - Cross-Site Scripting via Search Action Parameter
Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx.
by r0t3d3Vil
CVE-2005-4462 EXPLOITDB text VERIFIED
Tolva 0.1.0 - Remote File Inclusion via ROOT Parameter
PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.
by xbefordx