Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-4482 EXPLOITDB text VERIFIED
PortalApp 3.3 - Cross-Site Scripting via ret_page Parameter
Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.
by r0t
CVE-2005-4484 EXPLOITDB text VERIFIED
IntranetApp < 3.3 - Cross-Site Scripting via login.asp ret_page or content.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.
by r0t
CVE-2005-4484 EXPLOITDB text VERIFIED
IntranetApp < 3.3 - Cross-Site Scripting via login.asp ret_page or content.asp Parameters
Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.
by r0t
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4490 EXPLOITDB text VERIFIED
SCOOP! < 2.3 - Cross-Site Scripting via Multiple Parameters
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.
by r0t3d3Vil
CVE-2005-4573 EXPLOITDB text VERIFIED
Plogger Beta 2 - Remote Code Execution via config[basedir] Parameter
PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.
by Security .Net Information
CVE-2005-4563 EXPLOITDB text VERIFIED
Enterprise Heart Enterprise Connector 1.0.2 - SQL Injection
SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.
by Attila Gerendi
CVE-2005-4435 EXPLOITDB text VERIFIED
AbleDesign D-Man 3.x - Cross-Site Scripting via Title Parameter
Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by $um$id
EIP-2026-102565 EXPLOITDB text VERIFIED
Blender BlenLoader 2.x - File Processing Integer Overflow
by Damian Put
CVE-2005-4454 EXPLOITDB text VERIFIED
LiveJournal cleanhtml.pl < 1.129 - Cross-Site Scripting via Backslash Bypass in CSS Style Property
Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.
by Andrew Farmer
CVE-2005-4510 EXPLOITDB text VERIFIED
NetPublish Server 7 - Path Traversal
Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter.
by Andy Davis
CVE-2005-4419 EXPLOITDB text VERIFIED
Honeycomb Archive <3.0 - SQL Injection
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
by r0t3d3Vil
EIP-2026-115657 EXPLOITDB text VERIFIED
Microsoft Excel 95/97/2000/2002/2003/2004 - Memory Corruption (MS06-012)
by ad@heapoverflow.com
CVE-2005-4432 EXPLOITDB text VERIFIED
PlaySMS 0.8 - Cross-Site Scripting via err Parameter
Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the err parameter.
by mohajali2k4
CVE-2005-4516 EXPLOITDB text VERIFIED
PHP-Fusion 6.00.200-6.00.300 - Cross-Site Scripting via Sortby Parameter and IMG Tags
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web script or HTML via (1) the sortby parameter in members.php and (2) IMG tags.
by krasza
EIP-2026-110703 EXPLOITDB text VERIFIED
PHP Fusebox 3.0 - 'index.php' Cross-Site Scripting
by bogel & lukman
EIP-2026-110019 EXPLOITDB text VERIFIED
ODFaq 2.1 - 'faq.php' SQL Injection
by r0t
CVE-2005-4408 EXPLOITDB text VERIFIED
Miraserver <1.0 RC4 - SQL Injection
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.
by r0t
CVE-2005-4408 EXPLOITDB text VERIFIED
Miraserver <1.0 RC4 - SQL Injection
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.
by r0t
CVE-2005-4408 EXPLOITDB text VERIFIED
Miraserver <1.0 RC4 - SQL Injection
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.
by r0t