Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-109421 EXPLOITDB text VERIFIED
Mercury CMS 4.0 - Multiple Input Validation Vulnerabilities
by r0t3d3Vil
CVE-2005-4403 EXPLOITDB text VERIFIED
Marwel < 2.7 - SQL Injection via Show Parameter
SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter.
by r0t
CVE-2005-4361 EXPLOITDB text VERIFIED
Magnolia Content Management Suite 2.1 - Cross-Site Scripting via Search Query Parameter
Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
by r0t3d3Vil
CVE-2005-4780 EXPLOITDB LOW text VERIFIED
Fidra Lighthouse CMS <= 1.1.0 - Cross-Site Scripting via Search Parameter
Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology. [It] is an application server ... A technology like this cannot be susceptible to client-side cross-site-scripting-attacks on its own, but only applications created based on such a technology. This does not only apply to Lighthouse, but also to Perl, PHP or web applications based on Java Servlet technology." Since the original researcher is known to test demo pages and is sometimes inaccurate, it is likely that this issue will be REJECTED
by r0t3d3Vil
CVSS 3.7
CVE-2005-4400 EXPLOITDB text VERIFIED
Liferay Portal Enterprise <3.6.1 - XSS
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.
by r0t3d3Vil
CVE-2005-4399 EXPLOITDB text VERIFIED
Libertas Enterprise CMS < 3.0 - Cross-Site Scripting via Page Search Parameter
Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.
by r0t3d3Vil
CVE-2005-4363 EXPLOITDB text VERIFIED
Komodo CMS 2.1 - Cross-Site Scripting via Search Parameters
Cross-site scripting (XSS) vulnerability in the search engine in Komodo CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
by r0t3d3Vil
EIP-2026-108928 EXPLOITDB text VERIFIED
jPORTAL 2.2.1/2.3 Forum - 'forum.php' SQL Injection
by Zbigniew
CVE-2005-4365 EXPLOITDB text VERIFIED
FLIP 0.9.0.1029 - Cross-Site Scripting via Name Parameter and Frame Parameter
Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php.
by r0t3d3Vil
CVE-2005-4365 EXPLOITDB text VERIFIED
FLIP 0.9.0.1029 - Cross-Site Scripting via Name Parameter and Frame Parameter
Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php.
by r0t3d3Vil
CVE-2005-4527 EXPLOITDB text VERIFIED
Direct News 4.9 - SQL Injection via setLang Parameter
Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.
by r0t
CVE-2005-4390 EXPLOITDB text VERIFIED
contentserv < 3.1 - SQL Injection via StoryID Parameter
SQL injection vulnerability in index.php in ContentServ 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the StoryID parameter.
by r0t
CVE-2005-4385 EXPLOITDB text VERIFIED
Cofax 2.0 RC3 - Cross-Site Scripting via Search String Parameter
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.
by r0t3d3Vil
CVE-2005-4381 EXPLOITDB text VERIFIED
Caravel CMS < 3.0_beta_1 - Cross-Site Scripting via fileDN and folderviewer_attrs Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fileDN and (2) folderviewer_attrs parameters.
by r0t3d3Vil
CVE-2005-4375 EXPLOITDB text VERIFIED
Amaxus < 3 - Cross-Site Scripting via Change Parameter
Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.
by r0t3d3Vil
CVE-2005-4380 EXPLOITDB text VERIFIED
Bitweaver 1.1-1.1.1 beta - SQL Injection
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.
by r0t
CVE-2005-4380 EXPLOITDB text VERIFIED
Bitweaver 1.1-1.1.1 beta - SQL Injection
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.
by r0t
CVE-2005-4380 EXPLOITDB text VERIFIED
Bitweaver 1.1-1.1.1 beta - SQL Injection
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.
by r0t
CVE-2005-4380 EXPLOITDB text VERIFIED
Bitweaver 1.1-1.1.1 beta - SQL Injection
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.
by r0t
CVE-2005-4380 EXPLOITDB text VERIFIED
Bitweaver 1.1-1.1.1 beta - SQL Injection
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.
by r0t
EIP-2026-104982 EXPLOITDB text VERIFIED
Advanced Guestbook 2.x - Multiple Cross-Site Scripting Vulnerabilities
by Handrix
CVE-2005-4364 EXPLOITDB text VERIFIED
Hot Banana Web Content Mgmt Suite 5.3 - XSS
Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
by r0t3d3Vil
EIP-2026-100698 EXPLOITDB text VERIFIED
E-Publish 2.0 - Multiple Input Validation Vulnerabilities
by r0t3d3Vil
EIP-2026-100697 EXPLOITDB text VERIFIED
Community Enterprise 4.x - Multiple Input Validation Vulnerabilities
by r0t3d3Vil
CVE-2005-4378 EXPLOITDB text VERIFIED
Baseline CMS < 1.95 - SQL Injection via SiteNodeID Parameter
SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.
by r0t