Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-4496 EXPLOITDB text VERIFIED
SyntaxCMS < 1.2.1 - Cross-Site Scripting via Search Query Parameter
Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
by r0t3d3Vil
CVE-2005-4489 EXPLOITDB text VERIFIED
Scoop < 1.1_rc1 - Cross-Site Scripting via Type and Count Parameters
Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.
by r0t3d3Vil
CVE-2005-4489 EXPLOITDB text VERIFIED
Scoop < 1.1_rc1 - Cross-Site Scripting via Type and Count Parameters
Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.
by r0t3d3Vil
CVE-2005-4479 EXPLOITDB text VERIFIED
phpslash <= 0.8.1 - SQL Injection via article.php story_id Parameter
SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter.
by r0t3d3Vil
EIP-2026-110953 EXPLOITDB text VERIFIED
phpBB 2.0.18 - Cross-Site Scripting / Cookie Disclosure
by jet
CVE-2005-4478 EXPLOITDB text VERIFIED
papoo < 2.1.2 - SQL Injection via menuid forumid or reporeid_print Parameter
Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.
by r0t3d3Vil
CVE-2005-4478 EXPLOITDB text VERIFIED
papoo < 2.1.2 - SQL Injection via menuid forumid or reporeid_print Parameter
Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.
by r0t3d3Vil
CVE-2005-4478 EXPLOITDB text VERIFIED
papoo < 2.1.2 - SQL Injection via menuid forumid or reporeid_print Parameter
Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.
by r0t3d3Vil
CVE-2005-4477 EXPLOITDB text VERIFIED
papaya CMS <= 4.0.4 - Cross-Site Scripting via bab[searchfor] Parameter
Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.
by r0t3d3Vil
CVE-2005-4460 EXPLOITDB text VERIFIED
Beehive Forum <= 0.6.2 - Cross-Site Scripting via Name, Description, or Comment Fields
Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php.
by Alireza Hassani
CVE-2005-4476 EXPLOITDB text VERIFIED
OpenEdit < 4.0 - Cross-Site Scripting via oe-action or page Parameters
Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters.
by r0t3d3Vil
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t
CVE-2005-4488 EXPLOITDB text VERIFIED
Redakto WCMS < 3.2 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters.
by r0t3d3Vil
CVE-2005-4491 EXPLOITDB text VERIFIED
Sitekit CMS < 6.6 - Cross-Site Scripting via Query String and Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b) Request-call-back.html and (c) registration-form.html. NOTE: the vendor states "This issue was resolved by a minor update to Sitekit CMS v6.6, sanitising the html code and eradicating related security issues."
by r0t3d3Vil
CVE-2005-4491 EXPLOITDB text VERIFIED
Sitekit CMS < 6.6 - Cross-Site Scripting via Query String and Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b) Request-call-back.html and (c) registration-form.html. NOTE: the vendor states "This issue was resolved by a minor update to Sitekit CMS v6.6, sanitising the html code and eradicating related security issues."
by r0t3d3Vil
CVE-2005-4491 EXPLOITDB text VERIFIED
Sitekit CMS < 6.6 - Cross-Site Scripting via Query String and Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b) Request-call-back.html and (c) registration-form.html. NOTE: the vendor states "This issue was resolved by a minor update to Sitekit CMS v6.6, sanitising the html code and eradicating related security issues."
by r0t3d3Vil
CVE-2005-4483 EXPLOITDB text VERIFIED
SiteEnable < 3.3 - Cross-Site Scripting via ret_page Parameter
Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.
by r0t
CVE-2005-4486 EXPLOITDB text VERIFIED
Quantum Art QP7.Enterprise - SQL Injection
SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly Q-Publishing) allows remote attackers to execute arbitrary SQL commands via the p_news_id parameter to (1) news_and_events_new.asp and (2) news.asp. NOTE: on 20060227, the vendor disputed the accuracy of this report, saying that the p_news_id, news_and_events_new.asp, and news.asp are not specifically part of their product, although they could be dynamically generated through use of the product. Some investigation by CVE suggests evidence that the news_and_events_new.asp page has at least a forced invalid SQL syntax error, but this could not be repeated for news.asp
by r0t3d3Vil
CVE-2005-4486 EXPLOITDB text VERIFIED
Quantum Art QP7.Enterprise - SQL Injection
SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly Q-Publishing) allows remote attackers to execute arbitrary SQL commands via the p_news_id parameter to (1) news_and_events_new.asp and (2) news.asp. NOTE: on 20060227, the vendor disputed the accuracy of this report, saying that the p_news_id, news_and_events_new.asp, and news.asp are not specifically part of their product, although they could be dynamically generated through use of the product. Some investigation by CVE suggests evidence that the news_and_events_new.asp page has at least a forced invalid SQL syntax error, but this could not be repeated for news.asp
by r0t3d3Vil
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t
CVE-2005-4485 EXPLOITDB text VERIFIED
ProjectApp < 3.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
by r0t