Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106194 EXPLOITDB text VERIFIED
CourseForum Technologies ProjectForum 4.7 - Multiple Cross-Site Scripting Vulnerabilities
by r0t3d3Vil
CVE-2005-4276 EXPLOITDB text VERIFIED
Westell Versalink 327W - Denial of Service via Land Attack
Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.
by Justin M. Wray
CVE-2005-4275 EXPLOITDB text VERIFIED
Scientific Atlanta DPX2100 Cable Modem - Denial of Service via Land Attack
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.
by Justin M. Wray
EIP-2026-101036 EXPLOITDB text VERIFIED
Linksys Routers - LanD Packet Denial of Service
by Justin M. Wray
EIP-2026-101001 EXPLOITDB text VERIFIED
Cisco Catalyst Switches (Multiple Devices) - LanD Packet Denial of Service
by Justin M. Wray
CVE-2005-4259 EXPLOITDB text VERIFIED
ASPBB 0.4 - SQL Injection via TID, FORUM_ID, or PROFILE_ID Parameters
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
by Dj_Eyes
CVE-2005-4259 EXPLOITDB text VERIFIED
ASPBB 0.4 - SQL Injection via TID, FORUM_ID, or PROFILE_ID Parameters
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
by Dj_Eyes
CVE-2005-4259 EXPLOITDB text VERIFIED
ASPBB 0.4 - SQL Injection via TID, FORUM_ID, or PROFILE_ID Parameters
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
by Dj_Eyes
CVE-2005-4256 EXPLOITDB text VERIFIED
ASP-DEV XM Forum RC3 - Cross-Site Scripting via forum_title Parameter
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition, its accuracy is in question because "forum_title" does not appear to be specified in the source code for XM Forum RC3. It is possible, but not certain, that this is CVE-2004-2211.
by Dj_Eyes
CVE-2005-4241 EXPLOITDB text VERIFIED
VCD-db <= 0.98 - Cross-Site Scripting via Batch Parameter
Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.
by r0t3d3Vil
CVE-2005-4240 EXPLOITDB text VERIFIED
VCD-db <= 0.98 - SQL Injection via Search Parameter
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.
by r0t3d3Vil
CVE-2005-4244 EXPLOITDB text VERIFIED
Snipe Gallery < 3.1.4 - SQL Injection via Gallery ID or Image ID Parameter
SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.
by r0t
CVE-2005-4245 EXPLOITDB text VERIFIED
Snipe Gallery < 3.1.4 - Cross-Site Scripting via Search Keyword Parameter
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
by r0t
CVE-2005-4244 EXPLOITDB text VERIFIED
Snipe Gallery < 3.1.4 - SQL Injection via Gallery ID or Image ID Parameter
SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.
by r0t
CVE-2005-4246 EXPLOITDB text VERIFIED
Plogger Beta 2 - SQL Injection via id or page Parameter
SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter.
by r0t
CVE-2005-4247 EXPLOITDB text VERIFIED
Plogger Beta 2 - Cross-Site Scripting via Searchterms Parameter
Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter.
by r0t
CVE-2005-4228 EXPLOITDB text VERIFIED
phpwebgallery < 1.7.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
by r0t3d3Vil
CVE-2005-4228 EXPLOITDB text VERIFIED
phpwebgallery < 1.7.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
by r0t3d3Vil
CVE-2005-4228 EXPLOITDB text VERIFIED
phpwebgallery < 1.7.2 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
by r0t3d3Vil
CVE-2005-4211 EXPLOITDB text VERIFIED
phpCOIN 1.2.2 - Remote File Inclusion via $_CCFG[_PKG_PATH_DBSE] Variable
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.
by retrogod@aliceposta.it
CVE-2005-4212 EXPLOITDB text VERIFIED
phpCOIN 1.2.2 - Directory Traversal via $_CCFG[_PKG_PATH_DBSE] Variable
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.
by retrogod@aliceposta.it
CVE-2005-4239 EXPLOITDB text VERIFIED
PHP JackKnife < 2.21 - Cross-Site Scripting via sKeywords Parameter
Cross-site scripting (XSS) vulnerability in Search/DisplayResults.php in PHP JackKnife 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via URL-encoded values in the sKeywords parameter.
by r0t3d3Vil
CVE-2005-4251 EXPLOITDB text VERIFIED
mcGallery PRO 2.2 - SQL Injection via id start rand or album Parameters
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.
by r0t
CVE-2005-4250 EXPLOITDB text VERIFIED
mcgallery_pro 2.2 - Directory Traversal via Language Parameter
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.
by r0t
CVE-2005-4251 EXPLOITDB text VERIFIED
mcGallery PRO 2.2 - SQL Injection via id start rand or album Parameters
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.
by r0t